πΊπΈ
conrad10781
2026-05-17 15:53:19
(2 weeks ago)
nginx-dot-env
Web App Attack
Anonymous
2026-05-17 15:52:40
(2 weeks ago)
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:15:52:38 +0000] "GET /.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:15:52:38 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:15:52:38 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:15:52:38 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:15:52:38 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
π±π»
garmtech.com
2026-05-17 15:51:14
(2 weeks ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
π©πͺ
rh24
2026-05-17 15:28:01
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 207.241.173.116 (US/United States/-)
SQL Injection
π©πͺ
Selckie
2026-05-17 15:22:21
(2 weeks ago)
fail2ban: NGINX unusual impact
Web App Attack
πΊπΈ
JustMeHere
2026-05-17 15:06:22
(2 weeks ago)
[Sun May 17 11:06:17.896867 2026] [security2:error] [pid 54740:tid 54788] [client 207.241.173.116:16 ...
show more
[Sun May 17 11:06:17.896867 2026] [security2:error] [pid 54740:tid 54788] [client 207.241.173.116:16712] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "php.yorknation.com"] [uri "/secrets.json"] [unique_id "agnZaaOGe_VMeUoI0BqOLgAAABQ"]
...
show less
Web App Attack
Anonymous
2026-05-17 14:52:05
(2 weeks ago)
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:14:52:02 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:14:52:03 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:14:52:03 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:14:52:03 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:14:52:03 +0000] "GET /.env.local HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-17 13:48:03
(2 weeks ago)
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 207.241.173.116 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:13:48:02 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:13:48:02 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:13:48:02 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:13:48:02 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 207.241.173.116 - - [17/May/2026:13:48:02 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
π³π±
ParaBug
2026-05-17 13:23:51
(2 weeks ago)
207.241.173.116 - - [17/May/2026:15:23:50 +0200] "GET /secrets.json HTTP/1.1" 404 4149 "https://anti ...
show more
207.241.173.116 - - [17/May/2026:15:23:50 +0200] "GET /secrets.json HTTP/1.1" 404 4149 "https://antik-wagon.com/secrets.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
...
show less
Phishing
Brute-Force
Web App Attack
π§π¬
pa4080
2026-05-17 13:22:42
(2 weeks ago)
Detected by ModSecurity. Request URI: /.env
Web App Attack
πΊπΈ
mnsf
2026-05-17 12:05:19
(2 weeks ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
Anonymous
2026-05-17 04:27:37
(2 weeks ago)
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /.wp-config.php.swp HTTP/1.0" 404 156530 "-" " ...
show more
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /.wp-config.php.swp HTTP/1.0" 404 156530 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0"
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /.wp-config.php.swp HTTP/1.1" 404 26270 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0"
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /wp-config.php.bak HTTP/1.0" 404 156530 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0"
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 26271 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:150.0) Gecko/20100101 Firefox/150.0"
207.241.173.116 - - [17/May/2026:06:27:36 +0200] "GET /wp-config.php~ HTTP/1.0" 404 156526 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/150.0"
...
show less
Brute-Force
Web App Attack
π«π·
omartin
2026-05-17 04:24:04
(2 weeks ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
octageeks.com
2026-05-17 04:07:26
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 04:01:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 207.241.173.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 207.241.173.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 00:00:58.097615 2026] [security2:error] [pid 19162:tid 19162] [client 207.241.173.116:41720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradersworldmarket.com"] [uri "/.env.backup"] [unique_id "agk9elvdND4QfkyVOyZ85gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack