๐ง๐ช
sid3windr
2026-06-15 21:51:06
(1 day ago)
GET /.env (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐ง๐พ
lns.bz
2026-06-15 11:14:19
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:01:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:01:16.914372 2026] [security2:error] [pid 12078:tid 12078] [client 35.199.44.241:36308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawyerwest.com"] [uri "/.env"] [unique_id "ai-HHL4AUGpNxT79iskVvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 03:56:46
(2 days ago)
Aggressive web search of vulnerable pages: /.env.local /.env /api/.env /api/.env.local /api/v2/.env ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /api/.env /api/.env.local /api/v2/.env ...
show less
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-15 03:17:57
(2 days ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 01:08:09
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:25:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:24:59.099537 2026] [security2:error] [pid 28145:tid 28145] [client 35.199.44.241:35538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stern2.darkhorseyachting.com"] [uri "/.env.old"] [unique_id "ai8cKxf0Pln-U8BbzpfqHQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 17:27:59
(2 days ago)
[Sun Jun 14 19:27:58.048058 2026] [authz_core:error] [pid 177011:tid 177013] [client 35.199.44.241:5 ...
show more
[Sun Jun 14 19:27:58.048058 2026] [authz_core:error] [pid 177011:tid 177013] [client 35.199.44.241:59118] AH01630: client denied by server configuration: /var/www/html/.env
[Sun Jun 14 19:27:58.145582 2026] [authz_core:error] [pid 184398:tid 184421] [client 35.199.44.241:59126] AH01630: client denied by server configuration: /var/www/html/.env.local
[Sun Jun 14 19:27:58.554788 2026] [authz_core:error] [pid 177011:tid 177020] [client 35.199.44.241:59150] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Sun Jun 14 19:27:59.294369 2026] [authz_core:error] [pid 184398:tid 184407] [client 35.199.44.241:59208] AH01630: client denied by server configuration: /var/www/html/.env.production
[Sun Jun 14 19:27:59.295669 2026] [authz_core:error] [pid 177011:tid 177024] [client 35.199.44.241:59194] AH01630: client denied by server configuration: /var/www/html/.env.prod
...
show less
Web App Attack
๐ฌ๐ง
venus.launch.bz
2026-06-14 15:59:12
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.199.44.241 (US/United States/241.44. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.199.44.241 (US/United States/241.44.199.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Savvii
2026-06-14 15:49:16
(2 days ago)
20 attempts against mh-misbehave-ban on crop
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 06:52:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.44.241 (241.44.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:52:48.189289 2026] [security2:error] [pid 10358:tid 10358] [client 35.199.44.241:44086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srosa.danged.com"] [uri "/.env.backup.txt"] [unique_id "ai5PwO8y-nzE-C7yWR1q8gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 04:09:50
(3 days ago)
Scanning/Probing (103)
Request Overload (108)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 03:25:04
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack