Anonymous
2026-06-04 10:49:16
(3 months ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
π·π΄
StarTech Team
2026-05-30 16:06:25
(3 months ago)
Web App Atack
Web App Attack
Anonymous
2026-05-30 10:19:02
(3 months ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1, POST / HTTP/1.1
Hacking
Web App Attack
π©πͺ
Mykola Spesivtsev
2026-05-30 01:26:29
(3 months ago)
HTTP Tarpit detected bot activity:TargetPort:80, Path:/.env, Method:GET, UA:Mozilla/5.0 (X11; Linux ...
show more
HTTP Tarpit detected bot activity:TargetPort:80, Path:/.env, Method:GET, UA:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/5
show less
Port Scan
Web App Attack
Bad Web Bot
π©πͺ
Vegascosmetics
2026-05-27 21:55:23
(3 months ago)
Kingcopy(AI-IDS): IP is wandering around the site and acting suspiciously.
Bad Web Bot
Anonymous
2026-05-27 00:27:37
(3 months ago)
Unauthorized access (tcp/80/http)
Port Scan
Web App Attack
πΊπΈ
Rip
2026-05-25 08:11:23
(3 months ago)
Restricted File Access Attempts
Port Scan
Web App Attack
π©πͺ
Lino Project
2026-05-25 05:42:59
(3 months ago)
188.209.158.10 - - [25/May/2026:07:42:59 +0200] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (X11; ...
show more
188.209.158.10 - - [25/May/2026:07:42:59 +0200] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 23:55:04
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 19:54:59.608576 2026] [security2:error] [pid 12878:tid 12878] [client 188.209.158.10:53632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.229"] [uri "/.env"] [unique_id "ahI-U7spXNR-O1Ot6yA1gwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 23:39:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 19:39:45.751135 2026] [security2:error] [pid 22594:tid 22594] [client 188.209.158.10:50165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.154"] [uri "/.env"] [unique_id "ahI6wTrLLIGn5VK3sV3bmgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 23:24:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 19:24:34.419704 2026] [security2:error] [pid 22026:tid 22034] [client 188.209.158.10:63055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.79"] [uri "/.env"] [unique_id "ahI3Mls-W1r7VzO_Qjr2aAAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-23 23:09:28
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 188.209.158.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 19:09:25.333296 2026] [security2:error] [pid 25707:tid 25707] [client 188.209.158.10:59475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.4"] [uri "/.env"] [unique_id "ahIzpZ06DQ-zZuI1Dt5UwwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
cwytech
2026-05-21 11:59:25
(4 months ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/tpot-http-sensitive-files.
Bad Web Bot
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-05-21 11:44:20
(4 months ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-iad5-2)
Hacking
Bad Web Bot
πΊπΈ
Uzumaki
2026-01-06 22:21:00
(8 months ago)
Phishing Emails and Fraud
Phishing
Email Spam
Hacking
Spoofing
Exploited Host