Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=1031; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.devel ...
show more
Apache probe; attempts=1031; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.example/ | /.env.local | /.env.local/ | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.production/ | /.env.staging | /.env.swp | /.env.test | /.env/ | /.git-credentials | /.git-credentials/ | /.git/HEAD | /.git/HEAD/ | /.git/config | /.git/config/ | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /config/.env/ | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-23 07:57:07
(4 weeks ago)
20 attempts against mh-misbehave-ban on pf102962
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-07-23 07:50:48
(4 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-23 07:36:45
(4 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
dynamix
2026-07-23 07:10:46
(4 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:37:30
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.190.137.121 (121.137.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.190.137.121 (121.137.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:37:24.411962 2026] [security2:error] [pid 1784061:tid 1784061] [client 35.190.137.121:56108] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||api.feaverslane.com|F|2"] [data ".feaverslane.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "api.feaverslane.com"] [uri "/z9x8c7v6b5-debug-trigger-api.feaverslane.com"] [unique_id "amG2pBYxCQHys-AVA246FAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-23 06:31:44
(4 weeks ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ธ๐ช
vaia.cloud
2026-07-23 06:15:02
(4 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-07-23 05:59:25
(4 weeks ago)
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (c ...
show more
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" 35.190.137.121
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)" 35.190.137.121
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Applebot/0.1; +http://www.apple.com/go/applebot)" 35.190.137.121
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Diffbot/1.0; +https://diffbot.com)" 35.190.137.121
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" 35.190.137.121
35.190.137.121 - - [23/Jul/2026:00:59:24 -0500] "GET /.env.production HTTP/1.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-23 05:49:03
(4 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, git_exposure, actuator, aws_creds, ssh_keys, server_status, config_backup. Observed by 1 sensor(s); 438 hits.
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-22 16:31:25
(4 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 16:05:13
(4 weeks ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ซ๐ท
airstream
2026-07-22 16:02:48
(4 weeks ago)
Brute-force / scan on app.air-stream.io
Brute-Force
SSH
๐ซ๐ท
Octopuce
2026-07-22 15:48:29
(4 weeks ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /config/.env . ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /config/.env ...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 14:55:06
(4 weeks ago)
Excessive 404/403 errors
Brute-Force