๐บ๐ธ
TPI-Abuse
2026-07-24 06:17:20
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:17:08.666275 2026] [security2:error] [pid 3491130:tid 3491130] [client 104.28.254.131:50132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disnet-m.com"] [uri "/.env.local"] [unique_id "amMDZL8AIqZ_zna2jd7J4gAAAAk"], referer: https://www.google.com/search?q=disnet-m.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-24 05:15:49
(1 hour ago)
7 attacks on VC URLs, PHP URLs, env grabbing URLs, config grabbing URLs (type 2):
HEAD /.git/config ...
show more
7 attacks on VC URLs, PHP URLs, env grabbing URLs, config grabbing URLs (type 2):
HEAD /.git/config HTTP/1.1
HEAD /wp-config.php.bak HTTP/1.1
HEAD /.env.save HTTP/1.1
HEAD /secrets.json HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 02:17:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:17:28.726631 2026] [security2:error] [pid 3820129:tid 3820129] [client 104.28.254.131:27212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/.git/config"] [unique_id "amLLOOlZWomzBw2lcBB1OAAAAAo"], referer: https://www.google.com/search?q=alsdepot.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-07-23 22:12:00
(8 hours ago)
[FriJul2400:11:54.2667302026][security2:error][pid544745:tid544975][client104.28.254.131:0]ModSecuri ...
show more
[FriJul2400:11:54.2667302026][security2:error][pid544745:tid544975][client104.28.254.131:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.eutecne.ch.81-17-25-250.cpanel.site\"][uri\"/.env.bak\"][unique_id\"amKRqjgR5UTGzJbARVxNTAAAAQ8\"]\,referer:https://www.google.com/search\?q=www.eutecne.ch.81-17-25-250.cpanel.site
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-23 01:59:31
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 00:55:08
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env.local
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:55:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:55:01.845751 2026] [security2:error] [pid 1601642:tid 1601642] [client 104.28.254.131:65468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "technlunch.blog"] [uri "/.env"] [unique_id "amEgFbFGoXE1FZmbK7g8UgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 16:33:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 12:32:59.072316 2026] [security2:error] [pid 637728:tid 637741] [client 104.28.254.131:63232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soluciona.biz"] [uri "/.env.bak"] [unique_id "amDwu3Tp2k8tmlaKROjXGgAAAUs"], referer: https://www.google.com/search?q=soluciona.biz
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Al Coholic
2026-07-22 15:51:26
(1 day ago)
Automated report (2026-07-23T03:51:26+12:00). Caught probing for env file.
Hacking
Web App Attack
Open Proxy
๐บ๐ธ
Al Coholic
2026-07-22 15:51:25
(1 day ago)
Automated report (2026-07-23T03:51:26+12:00). Caught probing for exposed Git data.
Hacking
Web App Attack
Open Proxy
๐บ๐ธ
TPI-Abuse
2026-07-22 14:22:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 10:21:59.992899 2026] [security2:error] [pid 2225589:tid 2225589] [client 104.28.254.131:12247] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sublimationconsultants.ipostsocialmedia.com"] [uri "/.env"] [unique_id "amDSB4sWJ_ydZ8FCFS64FwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:57:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.28.254.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:57:21.873708 2026] [security2:error] [pid 892016:tid 892016] [client 104.28.254.131:22435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reettaanttila.com"] [uri "/.env"] [unique_id "amDMQat3-35uQRG5LhEjKgAAACA"], referer: https://www.google.com/search?q=reettaanttila.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-22 13:50:31
(1 day ago)
Restricted File Access Attempt. Matched phrase "config.json" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-22 10:11:03
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.git/config
Web App Attack
๐ง๐ท
chronos
2026-02-13 20:27:37
(5 months ago)
Generic malicious activity detected: Tentativa de varredura de porta TCP... | Proto: TCP | Port: 596 ...
show more
Generic malicious activity detected: Tentativa de varredura de porta TCP... | Proto: TCP | Port: 59601 | Location: Brazil, Florianรณpolis
show less
Port Scan
Hacking