๐ฉ๐ช
HERA - Operations
2025-07-06 21:26:59
(1 year ago)
argeforum - searching for vulnerable scripts: .env 2025/07/06 23:26:59
Web App Attack
๐ฉ๐ช
FeG Deutschland
2025-07-06 17:57:45
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
betternews.app
2025-07-06 12:20:34
(1 year ago)
"a web request contained keyword ".env"; Suspicious URL: /.env"
Web Spam
Blog Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sverson
2025-07-06 10:34:48
(1 year ago)
Automated report / Mutliple unauthorized attempts to access web resources
Hacking
Web App Attack
๐ซ๐ท
lindi
2025-07-06 00:10:16
(1 year ago)
trying to access .env file
...
Hacking
Web App Attack
Anonymous
2025-07-05 23:01:29
(1 year ago)
(mod_security) mod_security triggered on hostname [redacted] 5.230.253.188 (DE/Germany/vps68593a746b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 5.230.253.188 (DE/Germany/vps68593a746bc6d270381214.noezserver.de)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-07-05 20:26:45
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa ...
show more
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 05 16:26:37.021102 2025] [security2:error] [pid 1192:tid 1192] [client 5.230.253.188:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruralcommunitycare.org"] [uri "/.env"] [unique_id "aGmKfc2jV9H_RheQ0kJk_gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.Examensfragen.de
2025-07-05 20:24:39
(1 year ago)
Web Spam
Bad Web Bot
๐ซ๐ท
โจ
2025-07-05 19:37:02
(1 year ago)
Domain : tripoli-spain.org
Rule : env
2025-07-05 19:36:16 152.53.103.155 GET /.env - 443 - 162.158.8 ...
show more
Domain : tripoli-spain.org
Rule : env
2025-07-05 19:36:16 152.53.103.155 GET /.env - 443 - 162.158.86.162 HTTP/2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 - tripoli-spain.org 301 0 0 168 416 255 - 5.230.253.188
show less
Hacking
SQL Injection
๐บ๐ธ
Starburst SysOp Team
2025-07-04 11:11:04
(1 year ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-mnz6-3)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-04 03:10:37
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa ...
show more
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 03 23:10:30.973183 2025] [security2:error] [pid 15664:tid 15664] [client 5.230.253.188:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antitribu.com"] [uri "/.env"] [unique_id "aGdGJjM306Zu5OH6JfY1cAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-04 01:41:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa ...
show more
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 03 21:41:43.265605 2025] [security2:error] [pid 13315:tid 13315] [client 5.230.253.188:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kryptonome.com"] [uri "/.env"] [unique_id "aGcxV3EFJsbHHApTnwBjYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HERA - Operations
2025-07-03 19:55:55
(1 year ago)
argeforum - searching for vulnerable scripts: .env 2025/07/03 21:55:55
Web App Attack
Anonymous
2025-07-03 18:18:09
(1 year ago)
Restricted File Access Requests
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-07-03 16:06:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa ...
show more
(mod_security) mod_security (id:210492) triggered by 5.230.253.188 (188.0-255.253.230.5.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 03 12:06:45.159522 2025] [security2:error] [pid 19505:tid 19505] [client 5.230.253.188:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.env"] [unique_id "aGaqlXVMp6rNx6lHg5essQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack