🇬🇧
openstrike.co.uk
2026-08-08 05:13:56
(1 month ago)
17 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
Anonymous
2026-08-07 08:53:12
(1 month ago)
209.87.164.244 - - [07/Aug/2026:10:53:12 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macin ...
show more
209.87.164.244 - - [07/Aug/2026:10:53:12 +0200] "GET /.env HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
show less
Web App Attack
Anonymous
2026-08-07 08:25:55
(1 month ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-08-07T08:25:55.806Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-08-07T08:25:55.806Z | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0 | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack
🇩🇪
Ba-Yu
2026-08-07 08:08:02
(1 month ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
ArturShelby
2026-08-07 08:05:33
(1 month ago)
Critical file access: /.env
Web App Attack
🇬🇧
Aetherweb Ark
2026-08-07 08:04:29
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 209.87.164.244 (US/United States/-): N in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 209.87.164.244 (US/United States/-): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 07:58:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:58:21.921213 2026] [security2:error] [pid 18290:tid 18323] [client 209.87.164.244:31585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "104ventures.com"] [uri "/.env"] [unique_id "anWQHQRwBDij5liQJVL-QQAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 06:01:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:01:45.238944 2026] [security2:error] [pid 985471:tid 985471] [client 209.87.164.244:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colonybet.com"] [uri "/.env"] [unique_id "anV0yWMffoLwV48KnIWa9gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-08-07 06:00:00
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-07 05:23:20
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:23:12.926732 2026] [security2:error] [pid 2363949:tid 2363949] [client 209.87.164.244:23625] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "20dekopas.com"] [uri "/.env"] [unique_id "anVrwHMJwFKHg-juqWuqeQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
apislytics
2026-08-07 05:01:39
(1 month ago)
Automatic hard ban after repeated rate-limit abuse
Brute-Force
🇺🇸
Aurealize
2026-08-07 04:58:05
(1 month ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.env.
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 04:48:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:47:54.716456 2026] [security2:error] [pid 1313989:tid 1313989] [client 209.87.164.244:38363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astglobaltech.com"] [uri "/.env"] [unique_id "anVjes_JWoDbNi0pZJFK_QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 04:29:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:29:33.912227 2026] [security2:error] [pid 11313:tid 11313] [client 209.87.164.244:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.env"] [unique_id "anVfLSzUReOLgW3ngKYqzwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 04:08:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.87.164.244 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 00:08:09.566854 2026] [security2:error] [pid 1700635:tid 1700635] [client 209.87.164.244:41545] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advancedmotorsports.com"] [uri "/.env"] [unique_id "anVaKTA0ymgCAwdGmADyIAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack