πΊπΈ
TPI-Abuse
2024-07-26 11:40:35
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 26 07:40:27.314041 2024] [security2:error] [pid 12238:tid 12238] [client 38.242.233.72:52402] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legendcp.org"] [uri "/.env"] [unique_id "ZqOLK-EwzKkZFuvuMCBvkgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-26 10:09:46
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 26 06:09:40.131587 2024] [security2:error] [pid 1289520:tid 1289520] [client 38.242.233.72:46610] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tinkerlabyrinth.com"] [uri "/.env"] [unique_id "ZqN15DH-X1d5soBIkcstOwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
ITShelter Security
2024-07-26 04:44:31
(2 years ago)
Restricted File Access Attempt
2024/07/26 07:44:31 +03:00 req: GET /.env HTTP/1.1, host: ***.ru
2024 ...
show more
Restricted File Access Attempt
2024/07/26 07:44:31 +03:00 req: GET /.env HTTP/1.1, host: ***.ru
2024/07/26 07:44:44 +03:00 req: GET /.env HTTP/1.1, host: ***.pro
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-26 00:40:02
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 25 20:39:55.891588 2024] [security2:error] [pid 22955:tid 23036] [client 38.242.233.72:58992] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.135"] [uri "/.env"] [unique_id "ZqLwW2-e0uimijaP4S04jgAAAdY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-25 20:44:03
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 25 16:43:55.706659 2024] [security2:error] [pid 26897:tid 26897] [client 38.242.233.72:59704] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stricklinranch.com"] [uri "/.env"] [unique_id "ZqK5C-rJbucsO8b_XnRVsAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hydra-Shield.fr
2024-07-25 19:28:48
(2 years ago)
Directory Traversal on: /.env
Web App Attack
π¬π§
openstrike.co.uk
2024-07-19 05:12:30
(2 years ago)
17 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
π«π·
LRNP
2024-07-19 02:24:26
(2 years ago)
_:443 38.242.233.72 - - [19/Jul/2024:02:24:26 +0000] "GET /.env HTTP/1.1" 404 118 "-" "python-reques ...
show more
_:443 38.242.233.72 - - [19/Jul/2024:02:24:26 +0000] "GET /.env HTTP/1.1" 404 118 "-" "python-requests/2.22.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2024-07-18 23:27:44
(2 years ago)
Web APP Attack
Web App Attack
π¨π
backslash
2024-07-18 18:00:01
(2 years ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
π©πͺ
Hydra-Shield.fr
2024-07-18 15:50:35
(2 years ago)
Directory Traversal on: /.env
Web App Attack
πΊπΈ
Shouddy Tarano
2024-07-18 14:22:08
(2 years ago)
[Thu Jul 18 14:22:02.358909 2024] [authz_core:error] [pid 1826629:tid 140523411076864] [client 38.24 ...
show more
[Thu Jul 18 14:22:02.358909 2024] [authz_core:error] [pid 1826629:tid 140523411076864] [client 38.242.233.72:41016] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env
[Thu Jul 18 14:22:02.900026 2024] [authz_core:error] [pid 1826381:tid 140523234895616] [client 38.242.233.72:41032] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/
[Thu Jul 18 14:22:02.901512 2024] [authz_core:error] [pid 1826381:tid 140523234895616] [client 38.242.233.72:41032] AH01630: client denied by server configuration: /usr/share/httpd/noindex/index.html
[Thu Jul 18 14:22:06.105779 2024] [authz_core:error] [pid 1826629:tid 140523360720640] [client 38.242.233.72:41174] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/.env
[Thu Jul 18 14:22:06.585405 2024] [authz_core:error] [pid 1826382:tid 140523536901888] [client 38.242.233.72:41192] AH01630: client denied by server configuration: /var/www/erpcampestremty/public/
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-18 12:28:04
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 18 08:27:58.948603 2024] [security2:error] [pid 6096:tid 6096] [client 38.242.233.72:51088] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.happybookermusic.com"] [uri "/.env"] [unique_id "ZpkKTg9lbywsZbGK5Gbf5AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
gumbysoft
2024-07-18 12:11:52
(2 years ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
πΊπΈ
TPI-Abuse
2024-07-18 12:07:31
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 38.242.233.72 (vmi1964141.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 18 08:07:24.494461 2024] [security2:error] [pid 5049:tid 5049] [client 38.242.233.72:40838] [client 38.242.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perlcreative.com"] [uri "/.env"] [unique_id "ZpkFfNsFCzrkDCaFKDWrEAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack