๐ช๐ธ
alferez
2026-08-01 17:25:26
(1 hour ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:11:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:11:33.193923 2026] [security2:error] [pid 172297:tid 172297] [client 35.201.241.76:37158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pattymoorearmstrong.com"] [uri "/.env.production"] [unique_id "am4oxWCYTCX4sZUQlDQxxAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:44:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:43:51.068463 2026] [security2:error] [pid 15182:tid 15182] [client 35.201.241.76:41798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.market1st.bridgital.com"] [uri "/.env.bak"] [unique_id "am4iR-m3qjqxGs8C3Lax_gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-01 16:23:19
(2 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: crusader-worker/1 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
๐ณ๐ฟ
Tripwire
2026-08-01 16:14:11
(3 hours ago)
Scanning for exploits - /.env
Web App Attack
Anonymous
2026-08-01 16:11:51
(3 hours ago)
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worke ...
show more
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.145
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.144
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.144
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.dev HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.144
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.145
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.144
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.144
35.201.241.76 - - [01/Aug/2026:11:11:51 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "crusader-worker/1.0" 172.68.87.145
35.201.241.76 - - [01/Aug/2026
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-08-01 16:11:07
(3 hours ago)
GET /.env (Tarpitted for 4m20s, wasted 15.35kB)
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-01 16:02:12
(3 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.201.241.76 - - [01/Aug/2026:19:02:11 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.201.241.76 - - [01/Aug/2026:19:02:11 +0300] "GET /.env.production HTTP/1.1" 403 6298 "-" "crusader-worker/1.0"
show less
Web App Attack
Anonymous
2026-08-01 15:47:19
(3 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:33:04
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.241.76 (76.241.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:33:00.266823 2026] [security2:error] [pid 2331153:tid 2331153] [client 35.201.241.76:48860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "galego.anxo.org"] [uri "/.env.production"] [unique_id "am4RrPXi1QNFM0_FrjMhEAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 15:22:08
(3 hours ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ซ๐ท
masterguru
2026-08-01 15:13:21
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 14:28:25
(4 hours ago)
Web vulnerability probing: /.env
Web App Attack
๐ซ๐ท
COMAITE
2026-08-01 14:21:50
(4 hours ago)
Suspicious URL access.
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-01 14:21:45
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking