🇧🇾
lns.bz
2026-09-05 07:39:50
(4 hours ago)
.env scanning [BY]
Web App Attack
Anonymous
2026-09-05 07:15:54
(4 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /.env.prod | ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env.example | /.env.prod | /wp-config.php.swp
show less
Hacking
Web App Attack
🇩🇪
strxmpp
2026-09-05 07:13:04
(4 hours ago)
8.231.230.162 - - [05/Sep/2026:09:13:03 +0200] "GET /.env HTTP/1.1" 404 476 "-" "crusader-worker/1.0 ...
show more
8.231.230.162 - - [05/Sep/2026:09:13:03 +0200] "GET /.env HTTP/1.1" 404 476 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
🇺🇸
mc4bbs
2026-09-05 06:45:34
(5 hours ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /.env.bak -> 404 UA=""; GET /.env.backup -> 404 UA=""; GET /.env.prod -> 404 UA=""; GET /.env -> 404 UA=""; GET /actuator/configprops -> 404 UA=""
show less
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:18
(13 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:20:09
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:20:01.388691 2026] [security2:error] [pid 23005:tid 23078] [client 8.231.230.162:45892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jeflis.com"] [uri "/.env.dev"] [unique_id "aprhobbRlZcG9IeHctYDRgAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:12:38
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:12:29.956844 2026] [security2:error] [pid 17232:tid 17232] [client 8.231.230.162:44382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nearbyxm.com"] [uri "/.env.local"] [unique_id "aprRzQFvBhsC39duEkzukAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:43:00
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:42:52.695015 2026] [security2:error] [pid 11337:tid 11337] [client 8.231.230.162:42226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ideaofauniversity.website"] [uri "/.env"] [unique_id "aprK3PLuDSCgSoVOTL_W3gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:35:17
(22 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:28:48
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇩🇪
FeG Deutschland
2026-09-04 12:52:44
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:33:36
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:33:28.374933 2026] [security2:error] [pid 26450:tid 26450] [client 8.231.230.162:46836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.chitsey.com"] [uri "/.env.bak"] [unique_id "apq6mBr2hk67DzN9HR7MvQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 12:20:25
(23 hours ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:14:59
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.230.162 (162.230.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:14:54.414248 2026] [security2:error] [pid 18207:tid 18207] [client 8.231.230.162:43496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "missevelyn.com"] [uri "/.env.production"] [unique_id "apq2PhX9fQY8carqt-DskQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-04 11:47:52
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack