๐ซ๐ท
masterguru
2026-06-01 12:40:30
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-01 12:02:40
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-06-01 11:01:11
(2 days ago)
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:11:01:08 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:11:01:08 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:11:01:08 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:11:01:08 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:11:01:08 +0000] "GET /app/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-01 10:44:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 06:44:54.974441 2026] [security2:error] [pid 15158:tid 15158] [client 213.130.145.243:40684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fxztrader.com"] [uri "/admin/.env"] [unique_id "ah1ipj1SnTzoBCjRohpOIAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 09:30:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 08:02:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 04:02:38.209929 2026] [security2:error] [pid 21690:tid 21690] [client 213.130.145.243:35806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vincenzorusso.com"] [uri "/core/.env"] [unique_id "ah08nqDUEpjxd08FvMOTtAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-06-01 07:55:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (FR/France/-): 5 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (FR/France/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-01 07:38:28
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-06-01 07:37:13
(2 days ago)
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:07:37:10 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:07:37:10 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:07:37:10 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:07:37:10 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [01/Jun/2026:07:37:10 +0000] "GET /admin/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-01 07:14:29
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 03:14:22.725287 2026] [security2:error] [pid 24483:tid 24483] [client 213.130.145.243:64744] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ironmountainsports.com"] [uri "/api/.env"] [unique_id "ah0xThqGKbQ9TEWhCj_eTAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 06:53:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 02:53:12.423130 2026] [security2:error] [pid 7886:tid 7886] [client 213.130.145.243:50844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehudsonpress.com"] [uri "/admin/.env"] [unique_id "ah0sWAgy4S9Dy8BUswS74AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 06:06:09
(3 days ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 05:33:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 01:33:03.696980 2026] [security2:error] [pid 4999:tid 4999] [client 213.130.145.243:47768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ladymfashion.com"] [uri "/api/.env"] [unique_id "ah0Zj0BYr1BVoTh57ijPDwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-01 04:41:44
(3 days ago)
Web vulnerability probing: /admin/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 03:33:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 23:33:47.373855 2026] [security2:error] [pid 13201:tid 13201] [client 213.130.145.243:60310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3-6trucking.com"] [uri "/.env"] [unique_id "ahz9m-2GRfsNBSwUifxAdAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack