π¬π§
openstrike.co.uk
2026-09-27 05:15:34
(5 hours ago)
2 attacks on env grabbing URLs, config grabbing URLs:
GET /.env HTTP/1.1
GET /.htaccess HTTP/1.1
Hacking
π³π΄
jad-abuse
2026-09-26 12:33:51
(22 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, git_exposure, dotfile_probe. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 12:02:25
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:02:22.734212 2026] [security2:error] [pid 26392:tid 26392] [client 141.101.76.170:13647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clcmillvale.com"] [uri "/.env"] [unique_id "are0TuUEXtS5qWgAd7wAZgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 10:46:01
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 06:45:55.355742 2026] [security2:error] [pid 4354:tid 4354] [client 141.101.76.170:11556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pennylanefarmsauces.com"] [uri "/.git/config"] [unique_id "areiY5_gkuW7yQOUlkOsJAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 08:55:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:55:04.830645 2026] [security2:error] [pid 18344:tid 18344] [client 141.101.76.170:12607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vaxd.org"] [uri "/.env.production"] [unique_id "areIaIH4sU26LFwIlDe1rwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Ribeye375
2026-09-26 08:54:36
(1 day ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
π«π·
dynamix
2026-09-26 08:37:36
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 08:32:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:32:25.171247 2026] [security2:error] [pid 2913:tid 2928] [client 141.101.76.170:13070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vcschief.org"] [uri "/.env.local"] [unique_id "areDGUuRjyfnsSIRjEBMUgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 13:02:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 09:02:24.695586 2026] [security2:error] [pid 18070:tid 18070] [client 141.101.76.170:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/.env"] [unique_id "aqfwYHY707MB0x7rpsauFQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-10 12:53:16
(1 month ago)
Web App Attack
Anonymous
2026-08-07 05:32:33
(1 month ago)
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=24cc6132933937 ...
show more
Automatic report - Vulnerability scan
/forum7/memberlist.php?mode=viewprofile&u=4&sid=24cc6132933937ea59ce124d6f9b6afa
show less
Web App Attack
π©πͺ
paissangroup
2026-07-07 23:50:17
(2 months ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-27 20:20:23
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 141.101.76.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 16:20:18.014703 2026] [security2:error] [pid 18396:tid 18396] [client 141.101.76.170:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/.git/config"] [unique_id "akAwgm23rrYHGwGTb0c3-wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
sandra361
2026-05-25 21:59:01
(4 months ago)
Port scan detected: 7 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC= ...
show more
Port scan detected: 7 attempts across 1 ports (443). | Evidence: REAPER_TARPIT:IN=enp1s0f0 OUT= SRC=141.101.76.170 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=65155 DF PROTO=TCP SPT=14057 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
π©πͺ
femboy.cat
2026-05-08 01:51:41
(4 months ago)
Port scan to tcp/8443 from 141.101.76.170
Brute-Force