πΊπΈ
TPI-Abuse
2026-10-06 11:08:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:08:07.169809 2026] [security2:error] [pid 31265:tid 31265] [client 104.234.32.138:24945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.176"] [uri "/.env"] [unique_id "asTWl5HKa51i5s1Db22O_AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
Domainhizmetleri.com
2026-10-06 08:40:04
(4 days ago)
Source: DH Hunter (Honeypot) | Reason: HTTP Probe (80/tcp)
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 05:32:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:31:39.455499 2026] [security2:error] [pid 17249:tid 17249] [client 104.234.32.138:56325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.64"] [uri "/library/.env"] [unique_id "asSHu14ZrLL8PtM5dlOZsAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
azminawwar
2026-10-05 21:07:26
(5 days ago)
[104.234.32.138] triggered by honeypot on port [80], Timestamp [2026-10-05T21:07:26Z]METHOD=GET PATH ...
show more
[104.234.32.138] triggered by honeypot on port [80], Timestamp [2026-10-05T21:07:26Z]METHOD=GET PATH=/.env HTTP=HTTP/1.1 UA="Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/
show less
Port Scan
Hacking
πͺπΈ
librebit
2026-10-05 19:53:10
(5 days ago)
Brute force
Brute-Force
Anonymous
2026-10-05 19:48:56
(5 days ago)
"GET /conf/.env HTTP/1.1"
Hacking
Web App Attack
π«π·
0d0a
2026-10-05 17:39:13
(5 days ago)
Automated brute-force report from Fail2Ban
Web App Attack
π¦πΉ
Starburst SysOp Team
2026-10-05 13:05:42
(5 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-vie6-1)
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 12:55:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:55:10.132194 2026] [security2:error] [pid 3198:tid 3198] [client 104.234.32.138:25983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.224"] [uri "/wp-content/.env"] [unique_id "asOeLrmH3HOaJ4O_E_NJbQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 12:34:11
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:33:57.644530 2026] [security2:error] [pid 30650:tid 30650] [client 104.234.32.138:49313] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.188"] [uri "/vendor/.env"] [unique_id "asOZNbBEU6DRiHzxHE8ZkAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
XYCoderXY
2026-10-05 12:31:11
(5 days ago)
HTTP vulnerability scan: 2 requests between 2026-10-05 12:31:11 and 12:31:14 UTC. Targets: exposed s ...
show more
HTTP vulnerability scan: 2 requests between 2026-10-05 12:31:11 and 12:31:14 UTC. Targets: exposed secrets, config and source-control files. Examples: /local/.env, /app/.env. No legitimate visitor of this server sends these requests. Source blocked. - Lumerux Defense (lumerux.com), automated report. Contact: [email protected]
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 11:49:54
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:49:32.305614 2026] [security2:error] [pid 31843:tid 31843] [client 104.234.32.138:61029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.20"] [uri "/app/.env"] [unique_id "asOOzNLGn361jb-wA16g0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 11:28:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:27:54.806974 2026] [security2:error] [pid 26854:tid 26854] [client 104.234.32.138:64427] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.153"] [uri "/wp-content/.env"] [unique_id "asOJulqDu9OL3SYjGvpdyAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 10:57:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.234.32.138 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:57:27.634296 2026] [security2:error] [pid 31164:tid 31164] [client 104.234.32.138:58449] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.210"] [uri "/library/.env"] [unique_id "asOClzBZHkilW6RLLCXT2gAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
on-com
2026-10-05 10:45:42
(5 days ago)
URL scan
Brute-Force
Web App Attack