๐ฌ๐ง
openstrike.co.uk
2026-08-31 05:13:46
(2 days ago)
3 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
Anonymous
2026-08-31 04:15:32
(2 days ago)
Automated report (2026-08-31T00:15:32-04:00). Scraper detected. Caught probing for env file.
Bad Web Bot
Hacking
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-08-31 03:19:35
(2 days ago)
2026/08/31 04:19:33 [error] 380594#380594: *1721023 access forbidden by rule, client: 8.234.53.50, s ...
show more
2026/08/31 04:19:33 [error] 380594#380594: *1721023 access forbidden by rule, client: 8.234.53.50, server: bestasquadradas.org, request: "GET /.env HTTP/2.0", host: "bestasquadradas.org"
8.234.53.50 - - [31/Aug/2026:04:19:33 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "python-requests/2.34.2"
2026/08/31 04:19:33 [error] 380594#380594: *1721024 access forbidden by rule, client: 8.234.53.50, server: bestasquadradas.org, request: "GET /core/.env HTTP/2.0", host: "bestasquadradas.org"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-08-31 03:18:49
(2 days ago)
\[Mon Aug 31 05:18:47.238926 2026\] \[:error\] \[pid 15489:tid 140352451180288\] \[client 8.234.53.5 ...
show more
\[Mon Aug 31 05:18:47.238926 2026\] \[:error\] \[pid 15489:tid 140352451180288\] \[client 8.234.53.50:54370\] \[client 8.234.53.50\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "crx.it"\] \[uri "/.env"\] \[unique_id "apTyl1sJy5jS1ikHH@o8MwAAANE"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-31 03:05:26
(2 days ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-31 02:38:25
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
etu brutus
2026-08-31 02:29:43
(2 days ago)
8.234.53.50 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-30 23:39:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 19:39:18.057790 2026] [security2:error] [pid 17022:tid 17022] [client 8.234.53.50:63926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "watlab.com"] [uri "/.env"] [unique_id "apS_JlyFvIpsYjZs_3TU1QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-08-30 23:36:33
(2 days ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-08-30 23:30:12
(2 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ง๐พ
lns.bz
2026-08-30 23:22:20
(2 days ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-30 23:21:10
(2 days ago)
8.234.53.50 - - [30/Aug/2026:19:21:09 -0400] "GET /.env HTTP/1.1" 403 6271 "-" "python-requests/2.34 ...
show more
8.234.53.50 - - [30/Aug/2026:19:21:09 -0400] "GET /.env HTTP/1.1" 403 6271 "-" "python-requests/2.34.2"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 23:02:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 19:02:34.962967 2026] [security2:error] [pid 6062:tid 6062] [client 8.234.53.50:53526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ssion.com"] [uri "/.env"] [unique_id "apS2iib56duN2XXrg5d5FgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-30 23:02:33
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 22:46:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.53.50 (50.53.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:46:26.347741 2026] [security2:error] [pid 22026:tid 22026] [client 8.234.53.50:54046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summitartists.com"] [uri "/core/.env"] [unique_id "apSywhQCXF7eri-pWGwY3wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack