๐บ๐ธ
octageeks.com
2026-03-16 04:08:30
(3 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
stalker.to
2025-05-22 05:04:29
(1 year ago)
Datacenter Proxy
Web Spam
๐ฌ๐ง
openstrike.co.uk
2025-02-19 06:12:36
(1 year ago)
5 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
๐ช๐ธ
el-brujo
2025-02-18 19:55:19
(1 year ago)
18/Feb/2025:20:55:19.579021 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Feb/2025:20:55:19.579021 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 149.50.212.161] ModSecurity: Warning. Matched phrase "/.env" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.env found within REQUEST_FILENAME: /.env"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "www.hostench.eu"] [uri "/.env"] [unique_id "Z7Tlp21joschn55LxuocYQABMzA"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-18 19:36:06
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 14:36:01.795804 2025] [security2:error] [pid 198380:tid 198380] [client 149.50.212.161:63626] [client 149.50.212.161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jwilder.com"] [uri "/.env"] [unique_id "Z7ThIYM_XpsXDeSmQKFpqAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2025-02-18 17:29:33
(1 year ago)
149.50.212.161 - - [18/Feb/2025:17:29:27 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macin ...
show more
149.50.212.161 - - [18/Feb/2025:17:29:27 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
2025/02/18 17:29:31 [error] 3078605#3078605: *2632471 access forbidden by rule, client: 149.50.212.161, server: betatechnologies.info, request: "GET /.env HTTP/2.0", host: "blogs.betatechnologies.info"
149.50.212.161 - - [18/Feb/2025:17:29:31 +0000] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
๐บ๐ธ
rafled
2025-02-18 17:00:17
(1 year ago)
attempt to scan and scrape for env files and or files that expose the web app version
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-02-18 16:22:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 11:22:43.695585 2025] [security2:error] [pid 1997442:tid 1997442] [client 149.50.212.161:56077] [client 149.50.212.161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohwaitiforgot.com"] [uri "/.env"] [unique_id "Z7Sz05gFvKFxm_2ZQz3UZwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
S.O.B.A. Dev.
2025-02-18 16:04:44
(1 year ago)
Threat Blocked by BeeHive from (ASN:212238) (Network:CDNEXT) (Host:soba.dev) (Method:GET) (Protocol: ...
show more
Threat Blocked by BeeHive from (ASN:212238) (Network:CDNEXT) (Host:soba.dev) (Method:GET) (Protocol:HTTP/1.1) (Timestamp:2025-02-18T16:04:44Z)
show less
Web Spam
Brute-Force
Web App Attack
Anonymous
2025-02-18 15:34:14
(1 year ago)
Infected user bad webscan
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-02-18 15:23:48
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 149.50.212.161 (unn-149-50-212-161.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 18 10:23:40.826050 2025] [security2:error] [pid 6924:tid 6924] [client 149.50.212.161:51280] [client 149.50.212.161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.towermedia.net"] [uri "/.env"] [unique_id "Z7Sl_An_QP_xuvC6zPnVeQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2025-02-18 15:08:44
(1 year ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
teamsecure
2025-02-18 14:41:25
(1 year ago)
Banned for trying to access env
Web App Attack
๐ง๐ช
cmbplf
2025-02-18 14:31:00
(1 year ago)
118 requests to *.env
Brute-Force
Bad Web Bot
Anonymous
2025-02-18 14:06:14
(1 year ago)
Infected user bad webscan
Exploited Host