π·πΊ
DZBOT
2026-08-26 06:48:31
(57 minutes ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
π¬π§
openstrike.co.uk
2026-08-26 05:15:35
(2 hours ago)
10 attacks on config grabbing URLs (type 2), env grabbing URLs, PHP URLs, VC URLs:
GET /config.json ...
show more
10 attacks on config grabbing URLs (type 2), env grabbing URLs, PHP URLs, VC URLs:
GET /config.json HTTP/1.1
GET /.env.bak HTTP/1.1
GET /wp-config.php-backup HTTP/1.1
GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-08-26 04:53:29
(2 hours ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 04:12:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:12:21.764582 2026] [security2:error] [pid 5041:tid 5041] [client 35.192.160.19:3552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tyllo.com"] [uri "/.env"] [unique_id "ao5npRmw69pqY0Yo7c8wmQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 03:42:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 23:41:55.701523 2026] [security2:error] [pid 3626:tid 3626] [client 35.192.160.19:34504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tylercomputing.com"] [uri "/.env"] [unique_id "ao5gg_T8E3kdMAel6Ts1qQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 23:49:20
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 19:49:15.187495 2026] [security2:error] [pid 14977:tid 14977] [client 35.192.160.19:18286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twogocamping.com"] [uri "/.env"] [unique_id "ao4p-7-0PipaNRAzLgFeGwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 23:14:36
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 19:14:30.723655 2026] [security2:error] [pid 14784:tid 14784] [client 35.192.160.19:29382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twixmixy.com"] [uri "/.env"] [unique_id "ao4h1pxrcWQ5MLm1NAEjdAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-25 23:12:51
(8 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 22:21:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 18:21:16.790499 2026] [security2:error] [pid 5030:tid 5030] [client 35.192.160.19:44668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twinls.com"] [uri "/.env"] [unique_id "ao4VXGF6nkP8zDMPEhkbkAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 22:06:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 18:06:01.106767 2026] [security2:error] [pid 3726:tid 3726] [client 35.192.160.19:45476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twincitytn.com"] [uri "/.env"] [unique_id "ao4RyQxcJ25ystg9JaqsOAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 21:50:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:50:30.702960 2026] [security2:error] [pid 3062:tid 3062] [client 35.192.160.19:54086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twilighthackers.com"] [uri "/.env"] [unique_id "ao4OJvjed32KGYvtMl9tewAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 20:47:01
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.160.19 (19.160.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 16:46:52.771551 2026] [security2:error] [pid 13522:tid 13522] [client 35.192.160.19:59996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twccsolutions.com"] [uri "/.env"] [unique_id "ao3_POIpJ7To8NmoRJquqQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 20:16:34
(11 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-08-25 20:00:04
(11 hours ago)
suspicious request in access.log
Web App Attack
π©πͺ
LRob
2026-08-25 19:42:19
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-08-25 19:42 UTC
show less
Hacking
Web App Attack