๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 22:02:33
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-15.
show less
Web App Attack
SSH
Hacking
๐ฒ๐ฝ
LZ Servicios Digitales
2026-06-15 22:43:39
(1 week ago)
Reportado automรกticamente desde LiquidaZona Cloud WAF.
Brute-Force
๐ซ๐ฎ
geot
2026-06-15 13:56:16
(1 week ago)
64 requests, including :
GET /staging/.env HTTP/1.1
GET /production/.env HTTP/1.1
GET /.env HTTP/1. ...
show more
64 requests, including :
GET /staging/.env HTTP/1.1
GET /production/.env HTTP/1.1
GET /.env HTTP/1.1
GET /.env.demo HTTP/1.1
GET /.env.orig HTTP/1.1
GET /app/.env.dev HTTP/1.1
GET /htdocs/.env HTTP/1.1
GET /api/v2/.env HTTP/1.1
GET /api/v3/.env HTTP/1.1
GET /frontend/.env.local HTTP/1.1
GET /.env.example HTTP/1.1
GET /stage/.env HTTP/1.1
GET /.env.save HTTP/1.1
GET /backend/.env.local HTTP/1.1
GET /app/api/.env HTTP/1.1
GET /api/.env.bak HTTP/1.1
GET /api/.env.old HTTP/1.1
GET /config/.env HTTP/1.1
GET /dashboard/.env HTTP/1.1
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-15 10:15:07
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-06-15 06:47:44
(1 week ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-06-15 03:23:30
(1 week ago)
788 requests with url.path *.env
114 requests with url.path *sendgrid.env
Brute-Force
Bad Web Bot
๐ซ๐ท
โจ
2026-06-15 02:20:10
(1 week ago)
Domain : marcinthejoiner.co.uk
Rule : hack
2026-06-15 02:17:53 ***hidden-privacy*** GET /app/.env.ba ...
show more
Domain : marcinthejoiner.co.uk
Rule : hack
2026-06-15 02:17:53 ***hidden-privacy*** GET /app/.env.bak - 443 - 35.188.8.244 HTTP/1.1 Mozilla/5.0 (Linux; Android 5.1.1; Nexus 7 Build/LMY47V) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/43.0.2357.78 Safari/537.36 OPR/30.0.1856.93524 - marcinthejoiner.co.uk 404 0 0 13073 287 163 - -
show less
Hacking
SQL Injection
Brute-Force
๐ณ๐ฑ
Savvii
2026-06-15 01:54:49
(1 week ago)
20 attempts against mh-misbehave-ban on ec102966
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:08:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.8.244 (244.8.188.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.8.244 (244.8.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:08:19.931863 2026] [security2:error] [pid 22398:tid 22398] [client 35.188.8.244:40982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wurkroom.biz.smartstylehair.com"] [uri "/.env.backup"] [unique_id "ai9CcwIlW_42JrCvIj_kUwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:08:09
(1 week ago)
Abuse Detected (33)
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-06-14 23:51:09
(1 week ago)
Aggressive web search of vulnerable pages: /api/v2/.env /test/.env /uat/.env /api/.env /qa/.env ...
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-14 22:04:31
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-14
Web App Attack
SSH
Hacking
๐บ๐ฆ
Scientific Route
2026-06-14 19:13:53
(1 week ago)
35.188.8.244 - - [14/Jun/2026:22:13:52 +0300] "GET /.env HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Macinto ...
show more
35.188.8.244 - - [14/Jun/2026:22:13:52 +0300] "GET /.env HTTP/1.1" 404 456 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.84 Safari/537.36"
35.188.8.244 - - [14/Jun/2026:22:13:52 +0300] "GET /.env.bak HTTP/1.1" 404 456 "-" "W3C_Validator/1.305.2.12 libwww-perl/5.64"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 13:45:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.8.244 (244.8.188.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.8.244 (244.8.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 09:45:11.690312 2026] [security2:error] [pid 23533:tid 23533] [client 35.188.8.244:45904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/.env.qa"] [unique_id "ai6wZ2ApLieg7Kndblz1NwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
NoaQT
2026-06-14 05:47:07
(1 week ago)
2026-06-14T05:47:06.874352+00:00 ingress-1 haproxy[290]: 35.188.8.244:33746 [14/Jun/2026:05:47:06.87 ...
show more
2026-06-14T05:47:06.874352+00:00 ingress-1 haproxy[290]: 35.188.8.244:33746 [14/Jun/2026:05:47:06.873] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 469/468/0/0/0 0/0 "GET /.env.testing HTTP/1.1"
2026-06-14T05:47:06.893295+00:00 ingress-1 haproxy[290]: 35.188.8.244:33652 [14/Jun/2026:05:47:06.892] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 468/467/0/0/0 0/0 "GET /.env.save HTTP/1.1"
2026-06-14T05:47:06.948050+00:00 ingress-1 haproxy[290]: 35.188.8.244:33842 [14/Jun/2026:05:47:06.947] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 467/466/0/0/0 0/0 "GET /env.txt HTTP/1.1"
2026-06-14T05:47:06.949056+00:00 ingress-1 haproxy[290]: 35.188.8.244:33772 [14/Jun/2026:05:47:06.948] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 466/465/0/0/0 0/0 "GET /.env.template HTTP/1.1"
2026-06-14T05:47:07.083425+00:00 ingress-1 haproxy[290]: 35.188.8.244:33852 [14/Jun/2026:05:47:07.082] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 465/464/0/0/0 0/0 "
...
show less
DDoS Attack