π―π΅
Valhalla
2026-08-24 10:31:10
(9 hours ago)
/.env
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 07:23:18
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:23:12.164245 2026] [security2:error] [pid 30208:tid 30208] [client 157.230.12.173:52892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apuntesdeinversion.com"] [uri "/.env"] [unique_id "aovxYMOMW-aVJmID6EnuSQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
Abuse Buster
2026-08-24 05:32:00
(14 hours ago)
157.230.12.173 - - [24/Aug/2026:07:31:52 +0200] "GET /.env HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Window ...
show more
157.230.12.173 - - [24/Aug/2026:07:31:52 +0200] "GET /.env HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
157.230.12.173 - - [24/Aug/2026:07:31:54 +0200] "GET /_profiler/phpinfo HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
157.230.12.173 - - [24/Aug/2026:07:31:58 +0200] "GET /_profiler/open?file=config/packages/swiftmailer.yaml HTTP/2.0" 404 22 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-08-24 04:48:39
(14 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π«π·
arsonist
2026-08-24 02:31:26
(17 hours ago)
This IP accessed the path /.env, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-24 02:18:39
(17 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.sweetpuddingtrap.xyz | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-23 12:20:54
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: api.definitelynotahoneypot.top | URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-08-23 10:59:21
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 5 hits.
show less
Web App Attack
π©πͺ
big-cloud.nl
2026-08-23 10:58:19
(1 day ago)
Try to access /.env
Web App Attack
πΊπΈ
wordpresshosting.solutions
2026-08-22 20:02:19
(1 day ago)
Web app vulnerability scanning detected. Evidence: 157.230.12.173 - - [22/Aug/2026:20:02:07 +0000] " ...
show more
Web app vulnerability scanning detected. Evidence: 157.230.12.173 - - [22/Aug/2026:20:02:07 +0000] "GET /_profiler/phpinfo HTTP/1.1" 404 48801 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
157.230.12.173 - - [22/Aug/2026:20:02:17 +0000] "GET /_profiler/open?file=.env HTTP/1.1" 404 48819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
show less
Web App Attack
Anonymous
2026-08-22 17:07:18
(2 days ago)
http scanning for .env files
...
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 13:21:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:21:24.566630 2026] [security2:error] [pid 25714:tid 25729] [client 157.230.12.173:39972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aclarityforensics.com"] [uri "/.env"] [unique_id "aomiVPuI0lwCnVFQnpCocgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
vfAcceloReporter
2026-08-22 10:33:06
(2 days ago)
157.230.12.173 - - [22/Aug/2026:07:33:06 -0300] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windo ...
show more
157.230.12.173 - - [22/Aug/2026:07:33:06 -0300] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Exploited Host
π·πΊ
DZBOT
2026-08-22 07:19:38
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 07:12:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.12.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:12:33.650575 2026] [security2:error] [pid 28774:tid 28774] [client 157.230.12.173:58414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abramson-offner.com"] [uri "/.env"] [unique_id "aolL4YVunsjwY7IyzmdbmAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack