๐ช๐ธ
Gem
2026-06-19 22:13:11
(1 month ago)
Unauthorized web scan.
Web App Attack
๐ง๐ท
Sipo Chutรฃo
2026-06-19 03:00:01
(1 month ago)
/.env
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-06-16 12:40:12
(1 month ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 01:55:59
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiun ...
show more
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiunkab.go.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:55:53.322970 2026] [security2:error] [pid 31997:tid 31997] [client 103.132.230.107:33962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aticom.net"] [uri "/.env"] [unique_id "ajCtKQtGygSLldyuOg5QYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Selckie
2026-06-16 01:42:07
(1 month ago)
fail2ban: NGINX unusual impact
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 01:20:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiun ...
show more
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiunkab.go.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:20:21.325419 2026] [security2:error] [pid 5136:tid 5136] [client 103.132.230.107:47010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arthuryeung.net"] [uri "/.env"] [unique_id "ajCk1Ruk5jd6r-O5NEgqNgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-15 20:50:10
(1 month ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-15 20:43:03
(1 month ago)
103.132.230.107 - - [15/Jun/2026:23:38:38 +0300] "GET /.env HTTP/1.1" 404 733 "-" "Mozilla/5.0 (Wind ...
show more
103.132.230.107 - - [15/Jun/2026:23:38:38 +0300] "GET /.env HTTP/1.1" 404 733 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
103.132.230.107 - - [15/Jun/2026:23:43:03 +0300] "GET /.env HTTP/1.1" 404 728 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Web App Attack
Anonymous
2026-06-15 20:42:30
(1 month ago)
Fail2Ban triggered
Web App Attack
๐จ๐ญ
zynex
2026-06-15 11:44:52
(1 month ago)
URL Probing: /.env
Web App Attack
๐จ๐ญ
4server
2026-06-15 11:22:18
(1 month ago)
[MonJun1513:22:13.5321082026][security2:error][pid2968628:tid2968975][client103.132.230.107:0]ModSec ...
show more
[MonJun1513:22:13.5321082026][security2:error][pid2968628:tid2968975][client103.132.230.107:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.walter-worndli.ch\"][uri\"/.env\"][unique_id\"ai_gZQl2D9-7hdKZXaswZgAAAQ4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 19:00:49
(1 month ago)
(mod_security) mod_security (id:949110) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiun ...
show more
(mod_security) mod_security (id:949110) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiunkab.go.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 15:00:41.096717 2026] [security2:error] [pid 3876:tid 3876] [client 103.132.230.107:41002] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.delcano.org"] [uri "/.env"] [unique_id "ai76WcWAwieLg_uhSvEwkAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-13 19:19:09
(1 month ago)
[Sun Jun 14 05:19:07.920306 2026] [security2:error] [pid 814785] [client 103.132.230.107:37912] [cli ...
show more
[Sun Jun 14 05:19:07.920306 2026] [security2:error] [pid 814785] [client 103.132.230.107:37912] [client 103.132.230.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.env"] [unique_id "ai2tK7zON1f_hC2Kpr5FkwAAAAs"], referer: https://www.vap.com.au/.env
...
show less
Web App Attack
๐จ๐ญ
4server
2026-06-13 13:47:15
(1 month ago)
[SatJun1315:47:08.1150312026][security2:error][pid1444162:tid1444402][client103.132.230.107:0]ModSec ...
show more
[SatJun1315:47:08.1150312026][security2:error][pid1444162:tid1444402][client103.132.230.107:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.shadowdrummer.ch\"][uri\"/.env\"][unique_id\"ai1fXMTXu_ecbQ6e3s76uwAAAMo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 12:46:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiun ...
show more
(mod_security) mod_security (id:210492) triggered by 103.132.230.107 (107.230.132.103-ip.pool.madiunkab.go.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:46:02.112835 2026] [security2:error] [pid 6585:tid 6585] [client 103.132.230.107:39300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mpservice.com.sv"] [uri "/.env"] [unique_id "ai1RClWZcpa-vRqTNV4_BAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack