๐ณ๐ฑ
BlueWire Hosting
2026-05-11 21:09:02
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack
๐ซ๐ท
ISPLtd
2026-05-11 20:47:20
(3 weeks ago)
5.255.123.222 [11/May/2026:17:47:20 -0300] eu.mikeattwood.org:443 URL:/app/.env "GET /app/.env
5.255 ...
show more
5.255.123.222 [11/May/2026:17:47:20 -0300] eu.mikeattwood.org:443 URL:/app/.env "GET /app/.env
5.255.123.222 [11/May/2026:17:47:20 -0300] eu.mikeattwood.org:443 URL:/.aws/credentials "GET /.aws/credentials
...
show less
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-05-11 20:41:09
(3 weeks ago)
330 requests with url.path *secrets.json
327 requests with url.path *credentials.json
309 request ...
show more
330 requests with url.path *secrets.json
327 requests with url.path *credentials.json
309 requests with url.path *.aws/*
195 requests with url.path *.php.bak
187 requests with url.path */debug.log
185 requests with url.path *debug.log
140 requests with url.path *config.php
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-11 20:36:44
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 16:36:37.913867 2026] [security2:error] [pid 10803:tid 10803] [client 5.255.123.222:12332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadinglogan.com"] [uri "/backend/.env"] [unique_id "agI91fyLPxRnBkuvctikAAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 19:54:27
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 15:54:18.791670 2026] [security2:error] [pid 30091:tid 30091] [client 5.255.123.222:53060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.perlcreativedesign.com"] [uri "/.env"] [unique_id "agIz6sc2b5WrCR_hCYKL2QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-05-11 19:52:57
(3 weeks ago)
2026/05/11 19:52:55 [error] 877356#877356: *219507057 access forbidden by rule, client: 5.255.123.22 ...
show more
2026/05/11 19:52:55 [error] 877356#877356: *219507057 access forbidden by rule, client: 5.255.123.222, server: fn.binixo.es, request: "GET /.env HTTP/1.1", host: "binixo.bg"
2026/05/11 19:52:56 [error] 877360#877360: *219507093 access forbidden by rule, client: 5.255.123.222, server: fn.binixo.es, request: "GET /backend/.env HTTP/1.1", host: "binixo.bg"
2026/05/11 19:52:56 [error] 877360#877360: *219507094 access forbidden by rule, client: 5.255.123.222, server: fn.binixo.es, request: "GET /.env.local HTTP/1.1", host: "binixo.bg"
...
show less
Web App Attack
๐ฎ๐ณ
Genhost
2026-05-11 19:41:49
(3 weeks ago)
SCANNING OF PHP SHELL FILES
Brute-Force
SSH
๐ช๐ธ
loadsoporte
2026-05-11 19:35:55
(3 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฑ๐ป
garmtech.com
2026-05-11 19:34:01
(3 weeks ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฎ๐น
ciccio diddo
2026-05-11 19:28:05
(3 weeks ago)
CMS/WP Exploit multiple 404 port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 19:24:30
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 15:24:22.131171 2026] [security2:error] [pid 13669:tid 13669] [client 5.255.123.222:54310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.artisticheadstones.com"] [uri "/.env"] [unique_id "agIs5mdjJ43fxwiNhUZxrgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-11 19:10:45
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฌ๐ง
Apache
2026-05-11 18:12:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (NL/Netherlands/-): 5 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (NL/Netherlands/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 18:03:06
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 5.255.123.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 14:03:02.312133 2026] [security2:error] [pid 26326:tid 26326] [client 5.255.123.222:32490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.cthog.xyz"] [uri "/.env"] [unique_id "agIZ1gVJU3dAq8HaFZD3ogAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐บ
conseilgouz
2026-05-11 17:36:54
(3 weeks ago)
are-17 : Block hidden directories=>/backend/.env(/)
Hacking