๐ฌ๐ง
openstrike.co.uk
2024-06-18 05:13:03
(2 years ago)
25 attacks on env grabbing URLs:
GET /.env.example HTTP/1.1
Hacking
๐ฉ๐ช
Bedios GmbH
2024-06-17 13:13:51
(2 years ago)
Login credentials theft attempt
Hacking
๐ซ๐ฎ
Mr-Money
2024-06-17 11:29:08
(2 years ago)
173.249.55.151 - - [17/Jun/2024:13:28:48 +0200] "GET /.env HTTP/1.1" 404 4183 "-" "python-requests/2 ...
show more
173.249.55.151 - - [17/Jun/2024:13:28:48 +0200] "GET /.env HTTP/1.1" 404 4183 "-" "python-requests/2.25.1"
173.249.55.151 - - [17/Jun/2024:13:29:00 +0200] "GET /public/.env HTTP/1.1" 404 4181 "-" "python-requests/2.25.1"
173.249.55.151 - - [17/Jun/2024:13:29:07 +0200] "GET /staging/.env HTTP/1.1" 404 4181 "-" "python-requests/2.25.1"
...
show less
Hacking
SQL Injection
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2024-06-17 08:18:27
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (DE/Germany/vmi1515695.contabose ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (DE/Germany/vmi1515695.contaboserver.net): N in the last X secs
show less
Web App Attack
๐จ๐ญ
backslash
2024-06-17 08:10:02
(2 years ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-06-17 04:34:40
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 17 00:34:34.597785 2024] [security2:error] [pid 19362] [client 173.249.55.151:56712] [client 173.249.55.151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "computerizer.org"] [uri "/.env"] [unique_id "Zm-82j2fH7-PLIdoxH2jiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2024-06-17 04:33:25
(2 years ago)
Scanning for exploits - /.env
Web App Attack
Anonymous
2024-06-17 04:10:48
(2 years ago)
173.249.55.151 - - [17/Jun/2024:12:10:41 +0800] "GET /.env HTTP/1.1" 403 363 "-" "python-requests/2. ...
show more
173.249.55.151 - - [17/Jun/2024:12:10:41 +0800] "GET /.env HTTP/1.1" 403 363 "-" "python-requests/2.25.1" "-"
173.249.55.151 - - [17/Jun/2024:12:10:44 +0800] "GET /public/.env HTTP/1.1" 403 363 "-" "python-requests/2.25.1" "-"
173.249.55.151 - - [17/Jun/2024:12:10:48 +0800] "GET /staging/.env HTTP/1.1" 403 363 "-" "python-requests/2.25.1" "-"
...
show less
Web App Attack
๐ซ๐ท
sxvn
2024-06-17 02:39:07
(2 years ago)
2024-06-17 02:39:06,556 fail2ban.actions [864]: NOTICE [nginxrepeatoffender] Ban 173.249.55. ...
show more
2024-06-17 02:39:06,556 fail2ban.actions [864]: NOTICE [nginxrepeatoffender] Ban 173.249.55.151
2024-06-17 02:39:06,556 fail2ban.actions [864]: NOTICE [webexploits] Ban 173.249.55.151
2024-06-17 02:39:06,556 fail2ban.actions [864]: NOTICE [nginx-4xx] Ban 173.249.55.151
...
show less
Brute-Force
๐ต๐ฑ
strefapi_com
2024-06-17 02:38:14
(2 years ago)
Brute-force web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-16 23:35:05
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 16 19:35:00.182868 2024] [security2:error] [pid 517] [client 173.249.55.151:59874] [client 173.249.55.151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "macaraclub.az"] [uri "/.env"] [unique_id "Zm92pAu5fzp7fSAQIbya4AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-06-16 18:06:21
(2 years ago)
2024/06/16 20:06:19 [error] 27223#27223: *23426328 access forbidden by rule, client: 173.249.55.151, ...
show more
2024/06/16 20:06:19 [error] 27223#27223: *23426328 access forbidden by rule, client: 173.249.55.151, server: aide.bobelweb.eu, request: "GET /.env HTTP/1.1", host: "max.stage.bobelweb.eu"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-16 12:40:36
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 16 08:40:30.673392 2024] [security2:error] [pid 154258] [client 173.249.55.151:57586] [client 173.249.55.151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thevillageartcenter.pamelaweisberg.com"] [uri "/.env"] [unique_id "Zm7dPsk2j1yrh20_fp1-ZwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-16 10:06:53
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 16 06:06:49.701828 2024] [security2:error] [pid 1206] [client 173.249.55.151:39220] [client 173.249.55.151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soozebosire.com"] [uri "/.env"] [unique_id "Zm65Ob8fDgkdPAzNuMVW6AAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-16 08:13:45
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 173.249.55.151 (vmi1515695.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 16 04:13:40.868152 2024] [security2:error] [pid 29001] [client 173.249.55.151:34410] [client 173.249.55.151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sealcoatnj.com"] [uri "/.env"] [unique_id "Zm6etLvtFk0mTh3dMDb96QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack