๐ฌ๐ง
openstrike.co.uk
2026-06-09 05:14:40
(2 months ago)
9 attacks on env grabbing URLs:
GET /api/.env HTTP/1.1
Hacking
๐ฒ๐พ
Rizzy
2026-06-08 11:49:09
(2 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 08:00:13
(2 months ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-08 07:27:01
(2 months ago)
(caddyscan) Scanner path probe from 153.92.8.96 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 153.92.8.96 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 153.92.8.96 - - [08/Jun/2026:07:26:59 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [08/Jun/2026:07:26:59 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [08/Jun/2026:07:26:59 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [08/Jun/2026:07:26:59 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [08/Jun/2026:07:26:59 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
๐ฆ๐บ
paulshipley.com.au
2026-06-08 04:28:41
(2 months ago)
[Mon Jun 08 14:28:40.616547 2026] [security2:error] [pid 69455] [client 153.92.8.96:28292] [client 1 ...
show more
[Mon Jun 08 14:28:40.616547 2026] [security2:error] [pid 69455] [client 153.92.8.96:28292] [client 153.92.8.96] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "stkildashule.org.au"] [uri "/admin/.env"] [unique_id "aiZE-E2hF3fzUHs1s86gygAAAAE"]
...
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-07 22:07:36
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-06.
show less
Web App Attack
SSH
Hacking
๐ช๐ธ
elcruzado.es
2026-06-07 18:00:23
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted] 153.92.8.96 (ID/Indonesia/-)
SQL Injection
๐ณ๐ฑ
wlt-blocker
2026-06-07 16:08:48
(2 months ago)
Unauthorized access to webpage admin
Web App Attack
๐ซ๐ท
masterguru
2026-06-07 15:28:09
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-06-07 12:03:19
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-06-07 10:32:07
(2 months ago)
(caddyscan) Scanner path probe from 153.92.8.96 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 153.92.8.96 (ID/Indonesia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 153.92.8.96 - - [07/Jun/2026:10:32:04 +0000] "GET /laravel/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [07/Jun/2026:10:32:04 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [07/Jun/2026:10:32:04 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [07/Jun/2026:10:32:04 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.96 - - [07/Jun/2026:10:32:04 +0000] "GET /dev/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-07 09:28:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 05:28:35.356448 2026] [security2:error] [pid 16047:tid 16047] [client 153.92.8.96:45796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bullsalerts.com"] [uri "/core/.env"] [unique_id "aiU5w2PA32xcY8BLCoCCvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 09:01:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 05:01:01.977334 2026] [security2:error] [pid 963:tid 1019] [client 153.92.8.96:26746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epstransparency.org"] [uri "/backend/.env"] [unique_id "aiUzTQZPtED5SKXlVylESQAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 08:04:03
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 04:03:55.158482 2026] [security2:error] [pid 22040:tid 22040] [client 153.92.8.96:35856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swpppcal.com"] [uri "/core/.env"] [unique_id "aiUl60CQH8yRSrXzw76t0AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-07 06:03:53
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack