๐จ๐ญ
4server
2026-05-31 14:47:08
(3 days ago)
[SunMay3116:47:02.5765092026][security2:error][pid4092843:tid4093308][client157.230.233.200:0]ModSec ...
show more
[SunMay3116:47:02.5765092026][security2:error][pid4092843:tid4093308][client157.230.233.200:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"shadowdrummer.com\"][uri\"/api/.env\"][unique_id\"ahxJ5rZHXB8T77JBJ5AsLwAAAQo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-05-31 11:49:53
(3 days ago)
Web vulnerability probing: /new/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 10:28:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 06:28:33.695226 2026] [security2:error] [pid 25447:tid 25447] [client 157.230.233.200:37592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "restlesseye.com"] [uri "/core/.env"] [unique_id "ahwNUUoviu8dVorqA4arVwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
www.tana.it
2026-05-31 10:05:30
(3 days ago)
PHP scan
Web App Attack
Anonymous
2026-05-31 10:05:04
(3 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ฌ๐ง
Oakley
2026-05-31 09:38:06
(3 days ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-31 09:32:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 05:32:32.436118 2026] [security2:error] [pid 4865:tid 4865] [client 157.230.233.200:44528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tiesidebikinis.com"] [uri "/.env"] [unique_id "ahwAMHfLIetjg2F0A-N_-AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MM-bot
2026-05-31 08:19:25
(3 days ago)
URL-probe: HTTP/1.1 GET request on /member/.env (2026-05-31 10:19:25 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
Victor Lรณpez
2026-05-31 07:41:32
(3 days ago)
desdeotramirada.com 157.230.233.200 - - [31/May/2026:02:41:32 -0500] "GET /bank/.env HTTP/1.1" 404 2 ...
show more
desdeotramirada.com 157.230.233.200 - - [31/May/2026:02:41:32 -0500] "GET /bank/.env HTTP/1.1" 404 26289 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
desdeotramirada.com 157.230.233.200 - - [31/May/2026:02:41:32 -0500] "GET /new/.env HTTP/1.1" 404 26289 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
desdeotramirada.com 157.230.233.200 - - [31/May/2026:02:41:32 -0500] "GET /backend/.env HTTP/1.1" 404 26289 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-31 07:30:32
(3 days ago)
(y3) Failed access -byebye- from 157.230.233.200 (US/United States/-): (CF_ENABLE)
Hacking
Anonymous
2026-05-31 06:45:37
(3 days ago)
(caddyscan) Scanner path probe from 157.230.233.200 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 157.230.233.200 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:06:45:34 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:06:45:34 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:06:45:34 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:06:45:34 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:06:45:34 +0000] "GET /app/.env HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
Lino Project
2026-05-31 05:43:16
(3 days ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-05-31 05:13:10
(3 days ago)
18 attacks on env grabbing URLs:
GET /admin/.env HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-31 04:52:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.230.233.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 00:52:36.428415 2026] [security2:error] [pid 15430:tid 15430] [client 157.230.233.200:42680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kampinenlaw.com"] [uri "/backend/.env"] [unique_id "ahu-lOWlRUtiFKaTsnObwAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-31 04:33:50
(3 days ago)
(caddyscan) Scanner path probe from 157.230.233.200 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 157.230.233.200 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:04:33:48 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:04:33:48 +0000] "GET /bank/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:04:33:48 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:04:33:48 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 157.230.233.200 - - [31/May/2026:04:33:48 +0000] "GET /backend/.env HTTP/1.1"
show less
Port Scan