๐ซ๐ฎ
inlink.ltd
2026-08-01 17:26:08
(4 hours ago)
dot file probe
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 17:06:29
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ด
jad-abuse
2026-08-01 16:49:31
(5 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup. Observed by 1 sensor(s); 20 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:20:07
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:19:59.158974 2026] [security2:error] [pid 2205828:tid 2205828] [client 34.97.208.31:53766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yerevanpress.am"] [uri "/.env.local"] [unique_id "am4cr7-tweG3VAgR8scgSgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-01 14:39:40
(7 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ญ
4server
2026-08-01 14:28:49
(7 hours ago)
[SatAug0116:28:41.2429202026][security2:error][pid3838310:tid3838683][client34.97.208.31:0]ModSecuri ...
show more
[SatAug0116:28:41.2429202026][security2:error][pid3838310:tid3838683][client34.97.208.31:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"janus-advisory.ch.81-17-25-250.cpanel.site\"][uri\"/.env.old\"][unique_id\"am4Cmdwqm-2TszyAKfXJegAAAM8\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
sdos.es
2026-08-01 14:21:27
(7 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env.local"
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-01 13:15:01
(8 hours ago)
[Sat Aug 01 15:14:46.275045 2026] [security2:error] [pid 576805:tid 576981] [client 34.97.208.31:358 ...
show more
[Sat Aug 01 15:14:46.275045 2026] [security2:error] [pid 576805:tid 576981] [client 34.97.208.31:35840] [client 34.97.208.31] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.env" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env.production"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.aschi.at"] [uri "/.env.production"] [unique_id "am3xQJDK4v4mqIp_XGB0BQAAA1U"]
[Sat Aug 01 15:14:46.275067 2026] [security2:error] [pid 576805:tid 576993] [client 34.97.208.31:35834] [client 34.97.208.31] ModSecurity: Access denied with code 403 (phase 2). String match within ".asa/ .asax/ .ascx/ .axd/ .backu
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:14:28
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:14:22.788865 2026] [security2:error] [pid 4721:tid 4721] [client 34.97.208.31:43738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "muzenique.com.bridgital.com"] [uri "/.env.dev"] [unique_id "am3xLjKuBbjEq78Yay1SUgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 13:10:02
(8 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 13:00:53
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:56:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.208.31 (31.208.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:56:16.338444 2026] [security2:error] [pid 732482:tid 732482] [client 34.97.208.31:35416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.somaflow.okwellbeing.com"] [uri "/.env.save"] [unique_id "am3s8CwMKFL8NzfIXA0FpgAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 12:21:08
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-01 12:20:32
(9 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-01 12:12:50
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack