๐ซ๐ท
masterguru
2026-07-25 21:52:17
(29 minutes ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-07-25 21:16:23
(1 hour ago)
(caddyscan) Scanner path probe from 38.242.207.123 (DE/Germany/vmi2668569.contaboserver.net): 5 in t ...
show more
(caddyscan) Scanner path probe from 38.242.207.123 (DE/Germany/vmi2668569.contaboserver.net): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 38.242.207.123 - - [25/Jul/2026:21:16:15 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 38.242.207.123 - - [25/Jul/2026:21:16:16 +0000] "GET /env/.env HTTP/1.1"
[REDACTED] 200 2627 38.242.207.123 - - [25/Jul/2026:21:16:19 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 38.242.207.123 - - [25/Jul/2026:21:16:20 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 38.242.207.123 - - [25/Jul/2026:21:16:22 +0000] "GET /.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-25 21:12:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 17:12:17.353565 2026] [security2:error] [pid 1550929:tid 1550929] [client 38.242.207.123:52078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cultiplant.com"] [uri "/.env"] [unique_id "amUmsc58_1og9Wl3FaRf0gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Thibault Millant
2026-07-25 20:58:42
(1 hour ago)
2026/07/25 22:58:39 [error] 805016#805016: *932771 access forbidden by rule, client: 38.242.207.123, ...
show more
2026/07/25 22:58:39 [error] 805016#805016: *932771 access forbidden by rule, client: 38.242.207.123, server: certifications.millant.ovh, request: "GET /.env HTTP/1.1", host: "176.141.65.41"
2026/07/25 22:58:39 [error] 805014#805014: *932772 access forbidden by rule, client: 38.242.207.123, server: certifications.millant.ovh, request: "GET /env/.env HTTP/1.1", host: "176.141.65.41"
2026/07/25 22:58:39 [error] 805014#805014: *932773 access forbidden by rule, client: 38.242.207.123, server: certifications.millant.ovh, request: "GET /app/.env HTTP/1.1", host: "176.141.65.41"
2026/07/25 22:58:40 [error] 805014#805014: *932774 access forbidden by rule, client: 38.242.207.123, server: certifications.millant.ovh, request: "GET /api/.env HTTP/1.1", host: "176.141.65.41"
2026/07/25 22:58:41 [error] 805014#805014: *932776 access forbidden by rule, client: 38.242.207.123, server: certifications.millant.ovh, request: "GET /.env HTTP/1.1", host: "certifications.millant.ovh", referrer: "http://176.14
...
show less
Brute-Force
Exploited Host
Web App Attack
๐ฎ๐ช
Jim Keir
2026-07-25 20:53:36
(1 hour ago)
2026-07-25 20:53:36 38.242.207.123 File scanning, blocking 38.242.207.123 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 20:50:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:50:32.751313 2026] [security2:error] [pid 3214183:tid 3214194] [client 38.242.207.123:54958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flipkimmel.com"] [uri "/.env"] [unique_id "amUhmNnUFxn5hFl0OteftAAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 20:29:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:29:50.073569 2026] [security2:error] [pid 1178675:tid 1178675] [client 38.242.207.123:34804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srtmanagementservices.com"] [uri "/.env"] [unique_id "amUcvlQM2UAXrjYEfQnzGwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jfz-abuse
2026-07-25 20:18:21
(2 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ง๐ท
dominioz
2026-07-25 20:07:42
(2 hours ago)
2026-07-25 20:06:50 GET /.env - - 38.242.207.123 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+ ...
show more
2026-07-25 20:06:50 GET /.env - - 38.242.207.123 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:128.0)+Gecko/20100101+Firefox/128.0 - 200 1634
2026-07-25 20:06:51 GET /env/.env - - 38.242.207.123 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:128.0)+Gecko/20100101+Firefox/128.0 - 200 1634
2026-07-25 20:06:54 GET /app/.env - - 38.242.207.123 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:128.0)+Gecko/20100101+Firefox/128.0 - 200 1634
2026-07-25 20:06:58 GET /api/.env - - 38.242.207.123 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64;+rv:128.0)+Gecko/20100101+Firefox/128.0 - 200 1634
...
show less
Web App Attack
๐ฉ๐ช
iNetWorker
2026-07-25 20:00:24
(2 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐ซ๐ท
masterguru
2026-07-25 19:58:46
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-07-25 19:52:35
(2 hours ago)
[SatJul2521:52:30.0753212026][security2:error][pid115447:tid115520][client38.242.207.123:0]ModSecuri ...
show more
[SatJul2521:52:30.0753212026][security2:error][pid115447:tid115520][client38.242.207.123:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"manuclean.ch\"][uri\"/env/.env\"][unique_id\"amUT_iGfW2Tpqaw08D_JGQAAAIw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
masterguru
2026-07-25 19:22:00
(3 hours ago)
. Matched phrase "/.env" at REQUEST_URI. (210492-165)
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-25 19:04:18
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 18:48:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.207.123 (vmi2668569.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 14:48:07.050059 2026] [security2:error] [pid 2952745:tid 2952745] [client 38.242.207.123:57146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lighthousegive.com"] [uri "/.env"] [unique_id "amUE595PgBG9kzvSwhWV2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack