Anonymous
2026-08-01 20:17:12
(1 hour ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:23:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:23:11.403816 2026] [security2:error] [pid 2629105:tid 2629105] [client 35.228.20.8:44962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davedoeswater.com"] [uri "/.env.production"] [unique_id "am4rf3tEZUzYMfbSGFAt8QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 17:20:04
(4 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-01 16:50:46
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-08-01 16:45:40
(4 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:37:04
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:36:58.995873 2026] [security2:error] [pid 2588657:tid 2588657] [client 35.228.20.8:52240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/.env.local"] [unique_id "am4gqttSgqTLLVXxVZqPTAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-01 16:35:51
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.228.20.8 (FI/Finland/8.20.228.35.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 35.228.20.8 (FI/Finland/8.20.228.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฉ๐ช
raph
2026-08-01 16:27:38
(4 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 16:03:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 12:03:12.719981 2026] [security2:error] [pid 763548:tid 763548] [client 35.228.20.8:50826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sifnosgreekcatering.com"] [uri "/.env.prod"] [unique_id "am4YwD3gcT79gjdmpiUB-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-01 16:01:41
(5 hours ago)
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env.dev | UA: crusader-worker/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-08-01 15:47:57
(5 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-08-01 15:37:31
(5 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.irad2024.gr; logs=/var/log/httpd/domains/irad2024.gr.lo ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.irad2024.gr; logs=/var/log/httpd/domains/irad2024.gr.log; samples=/.env | /.env.example | /.env.old
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 15:21:40
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.20.8 (8.20.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 11:21:35.211229 2026] [security2:error] [pid 398401:tid 398401] [client 35.228.20.8:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brt.365soft.top"] [uri "/.env.local"] [unique_id "am4O_-b4HZBYsWbckS1fWwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 15:20:09
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-01 15:09:12
(6 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack