๐ซ๐ท
masterguru
2026-09-01 10:05:42
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-01 09:48:26
(3 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 09:39:56
(4 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.185.246.89 (US/United States/89.24 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.185.246.89 (US/United States/89.246.185.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 08:51:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:51:09.796463 2026] [security2:error] [pid 16743:tid 16743] [client 35.185.246.89:42872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrafoothillsrealty.georgetownca.com"] [uri "/.env.old"] [unique_id "apaR_S5i5u2CYQzCeO8K5gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-01 08:30:02
(5 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:11:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:11:30.421785 2026] [security2:error] [pid 31348:tid 31348] [client 35.185.246.89:36470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mldlnn.com"] [uri "/.env.bak"] [unique_id "apZ6ojYQfRsnXI6dKX6ZpAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:03:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.246.89 (89.246.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:03:02.082885 2026] [security2:error] [pid 20402:tid 20402] [client 35.185.246.89:53596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hollorancompanies.com"] [uri "/.env.backup"] [unique_id "apZqlrkweypxobIgIQjPHgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 04:51:27
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-01 04:00:29
(9 hours ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Email Spam
๐ฎ๐น
Inartis
2026-09-01 03:36:16
(10 hours ago)
35.185.246.89 - - [01/Sep/2026:05:36:14 +0200] "GET /.env HTTP/1.1" 403 5572 "-" "crusader-worker/1. ...
show more
35.185.246.89 - - [01/Sep/2026:05:36:14 +0200] "GET /.env HTTP/1.1" 403 5572 "-" "crusader-worker/1.0"
35.185.246.89 - - [01/Sep/2026:05:36:14 +0200] "GET /.env.save HTTP/1.1" 403 5572 "-" "crusader-worker/1.0"
35.185.246.89 - - [01/Sep/2026:05:36:14 +0200] "GET /.env.old HTTP/1.1" 403 5572 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 03:33:04
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /actuator/env HTTP/1.1, GET /e ...
show more
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /actuator/env HTTP/1.1, GET /env HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.dev HTTP/1.1, GET /crusader-404-probe HTTP/1.1, GET /_ignition/health-check HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.example HTTP/1.1, GET /storage/logs/laravel.log HTTP/1.1, GET /.env.backup HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
wbsouza
2026-09-01 03:21:30
(10 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฌ๐ง
consul.to
2026-09-01 03:07:26
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 03:06:15
(10 hours ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-09-01 03:00:19
(10 hours ago)
suspicious request in access.log
Web App Attack