π©πͺ
ger-stg-sifi1
2026-09-22 17:03:35
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π«π·
dynamix
2026-09-22 16:22:33
(16 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 16:19:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:19:52.985428 2026] [security2:error] [pid 23890:tid 23890] [client 8.230.26.214:37720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "praiseworthy.info"] [uri "/.env.prod"] [unique_id "arKqqEWjvcdYYyS4EqF2OAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-09-22 15:32:41
(17 hours ago)
env exposure on naturologie.com/.env.backup β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 14:52:21
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:52:14.227866 2026] [security2:error] [pid 7633:tid 7633] [client 8.230.26.214:53288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nationaljar.com"] [uri "/.env"] [unique_id "arKWHkoCnL2b4Ar0LLg-xQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:45:41
(18 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /.env | ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/wp-config.php.swp | /.env | /.env.save
show less
Hacking
Web App Attack
Anonymous
2026-09-22 14:38:44
(18 hours ago)
GET /.env.prod HTTP/1.1
...
Web App Attack
Anonymous
2026-09-22 14:15:02
(18 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-22 13:35:19
(19 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π©πͺ
SΓ©fora Srl
2026-09-22 13:12:46
(19 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
π¦πΉ
vikal
2026-09-22 13:06:36
(19 hours ago)
8.230.26.214 - - [22/Sep/2026:15:06:36 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-wo ...
show more
8.230.26.214 - - [22/Sep/2026:15:06:36 +0200] "GET /.env.production HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-22 13:04:26
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:04:20.285370 2026] [security2:error] [pid 28871:tid 28871] [client 8.230.26.214:47552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fatcaverecords.com"] [uri "/.env.save"] [unique_id "arJ81Cv8C4A86uNx3S5__gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 12:31:38
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.26.214 (214.26.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:31:34.086500 2026] [security2:error] [pid 12783:tid 12783] [client 8.230.26.214:51678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dokuzadabirdeniz.com.handankoc.net"] [uri "/.env.local"] [unique_id "arJ1Jh3SbX59uIXaK75wkwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
GoodOldTOS
2026-09-22 12:30:34
(20 hours ago)
Bad keywords detected in request: /.env
Web App Attack
π©πͺ
LRob
2026-09-22 12:28:40
(20 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env.prod (+10 more) | 2026-09-22 12:28 UTC
show less
Hacking
Web App Attack