π©πͺ
big-cloud.nl
2026-08-28 11:20:55
(22 minutes ago)
Try to access /@fs/..%252f..%252f..%252f..%252f..%252fapp/.env?raw??
Web App Attack
π³π±
middelkoopcc
2026-08-28 10:45:02
(58 minutes ago)
2026-08-28 12:43:34 GET /@fs/.env?raw?? [404] && 2026-08-28 12:43:34 GET /@fs/app/.env?raw?? [404] & ...
show more
2026-08-28 12:43:34 GET /@fs/.env?raw?? [404] && 2026-08-28 12:43:34 GET /@fs/app/.env?raw?? [404] && 2026-08-28 12:43:34 GET /@fs/proc/self/environ?raw?? [404] && 117 more within 20 minutes
show less
Web App Attack
πΈπͺ
vaia.cloud
2026-08-28 10:30:04
(1 hour ago)
crowdsecurity/CVE-2022-26134
Brute-Force
Web App Attack
Anonymous
2026-08-28 07:04:26
(4 hours ago)
Scan for .env Files at 2026-08-28T07:04:26+00:00
Web App Attack
Anonymous
2026-08-28 07:03:40
(4 hours ago)
Scan for .git Files at 2026-08-28T07:03:40+00:00
Web App Attack
Anonymous
2026-08-28 07:03:20
(4 hours ago)
Scan for .env Files at 2026-08-28T07:03:20+00:00
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 06:39:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 02:39:37.122913 2026] [security2:error] [pid 2042:tid 2042] [client 8.229.158.110:62934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.swampoodlegrounds.com"] [uri "/@fs/.env"] [unique_id "apEtKdh9nq-W2egSEHlT8AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 05:43:01
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:42:56.779297 2026] [security2:error] [pid 11446:tid 11446] [client 8.229.158.110:53970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tmcomic.flyingdodostudio.com"] [uri "/@fs/.env"] [unique_id "apEf4O_U5VS093vT5Cr4wQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-08-28 05:30:16
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.229.158.110 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 8.229.158.110 (US/United States/110.158.229.8.bc.googleusercontent.com)
show less
Bad Web Bot
π¬π§
openstrike.co.uk
2026-08-28 05:14:42
(6 hours ago)
482 attacks on env grabbing URLs, config grabbing URLs (type 2), password grabbing URLs, VC URLs, si ...
show more
482 attacks on env grabbing URLs, config grabbing URLs (type 2), password grabbing URLs, VC URLs, site downloads, PHP URLs:
GET /front/.env HTTP/1.1
GET /config/environment.json HTTP/1.1
GET /_next/../.aws/credentials HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /backup.sql HTTP/1.1
GET /phpinfo.php HTTP/1.1
show less
Hacking
Web App Attack
π¨π
π¨π Hosting
2026-08-28 05:10:48
(6 hours ago)
Automated WAF report: 150-175 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 05:00:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:00:18.096338 2026] [security2:error] [pid 18560:tid 18560] [client 8.229.158.110:43762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.devinfrymire.com"] [uri "/@fs/.env"] [unique_id "apEV4kbU1pVf70NZQMwAWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-28 03:14:16
(8 hours ago)
Excessive multi-domain requests
Brute-Force
πΈπͺ
vaia.cloud
2026-08-28 03:00:01
(8 hours ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 02:52:49
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.158.110 (110.158.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 22:52:44.370259 2026] [security2:error] [pid 7588:tid 7588] [client 8.229.158.110:62424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "llaira.com.artizandecor.com"] [uri "/@fs/.env"] [unique_id "apD3_FHknKL32Lu6Kd77KAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack