๐ฌ๐ง
consul.to
2026-08-25 20:34:24
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-08-25 18:04:01
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-25 14:53:19
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:30:14
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:30:06.425550 2026] [security2:error] [pid 17978:tid 17978] [client 82.25.120.218:23300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burdetteconsulting.com"] [uri "/.env"] [unique_id "ao2Kzv4jG9WlftpnbXN7zQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 12:16:09
(9 hours ago)
(caddyscan) Scanner path probe from 82.25.120.218 (IN/India/-): 5 in the last 3600 secs; Ports: *; D ...
show more
(caddyscan) Scanner path probe from 82.25.120.218 (IN/India/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 82.25.120.218 - - [25/Aug/2026:12:16:05 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [25/Aug/2026:12:16:05 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [25/Aug/2026:12:16:05 +0000] "GET /backup/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [25/Aug/2026:12:16:05 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [25/Aug/2026:12:16:05 +0000] "GET /test/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-25 12:06:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:05:56.875489 2026] [security2:error] [pid 9667:tid 9667] [client 82.25.120.218:40914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cucciniello.com"] [uri "/api/.env"] [unique_id "ao2FJFcNBcBLJUpLGYpWDAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 00:34:55
(21 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
Apache
2026-08-25 00:21:45
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (IN/India/-): 5 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (IN/India/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-24 23:48:32
(22 hours ago)
(mod_security) mod_security (id:949110) triggered by 82.25.120.218 (IN/India/-): N in the last X sec ...
show more
(mod_security) mod_security (id:949110) triggered by 82.25.120.218 (IN/India/-): N in the last X secs
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-08-24 22:54:31
(23 hours ago)
Aggressive web search of vulnerable pages: /backup/.env /.env /dev/.env /member/.env /test/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 22:31:52
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 82.25.120.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:31:44.059617 2026] [security2:error] [pid 16877:tid 16877] [client 82.25.120.218:38824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonetarot.com"] [uri "/.env"] [unique_id "aozGUCi16I8ulqTTIZ61hQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-24 19:51:04
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-24 19:12:36
(1 day ago)
(caddyscan) Scanner path probe from 82.25.120.218 (IN/India/-): 5 in the last 3600 secs; Ports: *; D ...
show more
(caddyscan) Scanner path probe from 82.25.120.218 (IN/India/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 82.25.120.218 - - [24/Aug/2026:19:12:31 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [24/Aug/2026:19:12:31 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [24/Aug/2026:19:12:31 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [24/Aug/2026:19:12:31 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 82.25.120.218 - - [24/Aug/2026:19:12:31 +0000] "GET /member/.env HTTP/1.1"
show less
Port Scan
๐ซ๐ท
masterguru
2026-08-24 17:54:47
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-24 17:00:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack