π¬π§
openstrike.co.uk
2026-06-16 05:15:30
(8 hours ago)
3 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
πΊπΈ
TPI-Abuse
2026-06-15 17:50:06
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 13:49:59.531277 2026] [security2:error] [pid 16051:tid 16051] [client 2a02:c207:2323:8721::1:52782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joesteiner.com"] [uri "/.env"] [unique_id "ajA7R2Eygm0ytnmHjsRU7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 16:26:35
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 12:26:27.873663 2026] [security2:error] [pid 6034:tid 6034] [client 2a02:c207:2323:8721::1:40318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plumeriatc.org"] [uri "/.env"] [unique_id "ajAns6-YRZQs9GDBBJwmdgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
dbmwebdesign
2026-06-15 16:25:24
(21 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 15:59:33
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 11:59:28.021877 2026] [security2:error] [pid 1564:tid 1564] [client 2a02:c207:2323:8721::1:44070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singleslidestrategy.com"] [uri "/api/.env"] [unique_id "ajAhYGrajnuqz4MRbM2MQAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
SLSLLC
2026-06-15 14:23:54
(23 hours ago)
2a02:c207:2323:8721::1 - - [15/Jun/2026:14:23:53 +0000] "GET /.env HTTP/1.1" 403 2113 "-" "Go-http-c ...
show more
2a02:c207:2323:8721::1 - - [15/Jun/2026:14:23:53 +0000] "GET /.env HTTP/1.1" 403 2113 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Web App Attack
π©πͺ
YF
2026-06-15 14:20:11
(23 hours ago)
Environment file probe
Web App Attack
π³π±
e.fierstra
2026-06-15 14:17:30
(23 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 14:14:42
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 10:14:35.262928 2026] [security2:error] [pid 5361:tid 5361] [client 2a02:c207:2323:8721::1:46502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyber507.net"] [uri "/app/.env"] [unique_id "ajAIy4mO9AR45IIP5zGbOgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 13:03:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 09:03:31.342589 2026] [security2:error] [pid 24225:tid 24225] [client 2a02:c207:2323:8721::1:35600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avrknives.com"] [uri "/.env"] [unique_id "ai_4I9T24KCA-6q9HI1_5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 11:47:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:47:35.726838 2026] [security2:error] [pid 26088:tid 26088] [client 2a02:c207:2323:8721::1:57326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "underraided.com"] [uri "/app/.env"] [unique_id "ai_mV_r_WVt0CPKkcpLZ-AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-06-15 11:01:30
(1 day ago)
[15/Jun/2026:12:25:38.690752 +0200] ai_TIuXoHPVf0aVLjU_cCQAAAAE 2a02:c207:2323:8721::1 50724 127.0.0 ...
show more
[15/Jun/2026:12:25:38.690752 +0200] ai_TIuXoHPVf0aVLjU_cCQAAAAE 2a02:c207:2323:8721::1 50724 127.0.0.1 7081
[15/Jun/2026:12:25:39.290014 +0200] ai_TI-Oh6n87Hk2FQyCagAAAAAU 2a02:c207:2323:8721::1 51048 127.0.0.1 7081
[15/Jun/2026:13:01:29.252867 +0200] ai_biRxYG6Uqwie2YoS1WgAAAAI 2a02:c207:2323:8721::1 57412 127.0.0.1 7081
...
show less
Web App Attack
π©πͺ
4server
2026-06-15 09:09:47
(1 day ago)
[MonJun1511:09:45.7694932026][security2:error][pid4004233:tid4004265][client2a02:c207:2323:8721::1:0 ...
show more
[MonJun1511:09:45.7694932026][security2:error][pid4004233:tid4004265][client2a02:c207:2323:8721::1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"subitotraslochi.ch\"][uri\"/api/.env\"][unique_id\"ai_BWQ5ZtYNOZvoiJcJfKQAAABU\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 08:48:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserve ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:c207:2323:8721::1 (vmi3238721.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:48:50.411634 2026] [security2:error] [pid 6644:tid 6644] [client 2a02:c207:2323:8721::1:55248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "themillercsefoundation.org"] [uri "/.env"] [unique_id "ai-8cjkxQ2Fi_znEv0DbEQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-06-15 08:41:18
(1 day ago)
Web App Attack Exploid from 2a02:c207:2323:8721::1
Web App Attack