๐ง๐ช
madeit
2026-09-04 14:31:42
(1 day ago)
Web App Attack
๐ง๐ช
madeit
2026-08-06 05:20:05
(1 month ago)
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-07-02 01:31:39
(2 months ago)
Vulnerability scan - GET /__web_secure_probe_1782955893766926755.babelrc HTTP/2.0
Hacking
Anonymous
2026-05-22 21:22:44
(3 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 18:26:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 14:26:49.190073 2026] [security2:error] [pid 26092:tid 26092] [client 104.23.253.139:10243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lazymanvegan.com"] [uri "/.env.development.local"] [unique_id "adFX6dOyOElMb2cUFKLNfwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 03:20:51
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 23:20:45.409392 2026] [security2:error] [pid 3067:tid 3067] [client 104.23.253.139:9298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whaletailpuckerbutt.com"] [uri "/admin/.env"] [unique_id "adCDjZ2VaDOi_9Ks_IkusQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-03-24 19:16:39
(5 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-stl2-14)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:27:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:27:27.146483 2026] [security2:error] [pid 32274:tid 32274] [client 104.23.253.139:10905] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.readyremotely.com"] [uri "/app/.env"] [unique_id "ab3z_0kp8X_kOD7Fs9XtvwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:56:42
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:56:36.420189 2026] [security2:error] [pid 32668:tid 32668] [client 104.23.253.139:11483] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocky-ridgeco.com"] [uri "/.env.json"] [unique_id "abz9tOjzGXtwikd4JQk42wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:05:57
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:05:52.674249 2026] [security2:error] [pid 21245:tid 21245] [client 104.23.253.139:13030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityengraving.com"] [uri "/.env.test"] [unique_id "abzx0LeVr8OehNSPMLxb2QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 05:08:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 01:08:25.668681 2026] [security2:error] [pid 23246:tid 23246] [client 104.23.253.139:9717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.universitydental.org"] [uri "/var/www/.env"] [unique_id "abzWSVLE7zk8Pnit3k9vrgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:15:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:15:18.091442 2026] [security2:error] [pid 4890:tid 4890] [client 104.23.253.139:11383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.glolady.com"] [uri "/.env.old"] [unique_id "abzJ1vkt3cUxrvS1vL1kCQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:56:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:56:41.346492 2026] [security2:error] [pid 19462:tid 19462] [client 104.23.253.139:13453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.icwcruisersguide.com"] [uri "/.env.dev"] [unique_id "abzFeX99hgbGfb5XlUxa1AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:38:10
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:38:02.943092 2026] [security2:error] [pid 18502:tid 18502] [client 104.23.253.139:9463] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.majersigns.com"] [uri "/.env.php"] [unique_id "abyk-qKA6wr0h33FsDKt6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:56:19
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.253.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:56:12.246395 2026] [security2:error] [pid 18797:tid 18797] [client 104.23.253.139:12512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.jazzycatty.com"] [uri "/.env.backup"] [unique_id "abybLF2vdjTrYREBeJaojAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack