๐ฉ๐ช
barbarella
2026-10-06 08:42:43
(9 hours ago)
Configuration snooping in .env file (GET /new/.env)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 18:55:12
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 14:54:51.174607 2026] [security2:error] [pid 25268:tid 25268] [client 104.234.32.136:48437] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.89"] [uri "/src/.env"] [unique_id "asPye_v78FtDtvtU1lNT2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 17:05:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 13:04:54.479409 2026] [security2:error] [pid 19312:tid 19312] [client 104.234.32.136:33171] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.172"] [uri "/protected/.env"] [unique_id "asPYthu_lSXSReC9GD7DtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 16:44:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 12:44:00.499783 2026] [security2:error] [pid 30292:tid 30292] [client 104.234.32.136:35447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.233"] [uri "/www/.env"] [unique_id "asPT0JXSKmDKctZ9e0neuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wristhulk
2026-10-05 16:36:47
(1 day ago)
Honeypot: 20 RDP connection probes in 1 hour on OpenCanary honeypot (port 3389). (56 attempts)
Brute-Force
๐บ๐ธ
IndigoRidge
2026-10-05 16:22:25
(1 day ago)
Knock-Knock RDP honeypot activity; time=2026-10-05 16:17:45; username=hello
Brute-Force
๐บ๐ธ
wristhulk
2026-10-05 16:21:44
(1 day ago)
Honeypot: RDP brute-force on OpenCanary honeypot (port 3389). Username: 'hello'. (16 attempts)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 14:46:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:45:56.034890 2026] [security2:error] [pid 22328:tid 22328] [client 104.234.32.136:49585] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.15"] [uri "/wp-content/.env"] [unique_id "asO4JE9sVAqv4ICNCtG_wgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:03:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:03:40.971165 2026] [security2:error] [pid 16499:tid 16499] [client 104.234.32.136:64997] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.141"] [uri "/library/.env"] [unique_id "asOuPMrEcmF2MpY2yJNlHQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:49:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:49:29.672503 2026] [security2:error] [pid 31979:tid 31979] [client 104.234.32.136:53231] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.20"] [uri "/library/.env"] [unique_id "asOOyacoRWQYcUJIdhd9swAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:28:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:27:59.998945 2026] [security2:error] [pid 28601:tid 28601] [client 104.234.32.136:48149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.153"] [uri "/src/.env"] [unique_id "asOJv4zdoopQfnejbcKRPQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-10-05 10:45:38
(1 day ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 10:30:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:30:06.928329 2026] [security2:error] [pid 28768:tid 28768] [client 104.234.32.136:44881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.115"] [uri "/wp-admin/.env"] [unique_id "asN8Ln09l00-T5hWk08cFgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 08:14:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 04:14:29.458454 2026] [security2:error] [pid 26493:tid 26493] [client 104.234.32.136:62461] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.104"] [uri "/newsite/.env"] [unique_id "asNcZYiTU3Qr1OhSyX-WiQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 01:35:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:35:40.445661 2026] [security2:error] [pid 29680:tid 29680] [client 104.234.32.136:54435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.229"] [uri "/admin/.env"] [unique_id "asL-7NlYubVHasAhotmwtgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack