๐บ๐ธ
kosada.com
2026-08-26 17:52:32
(5 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-24 04:56:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink ...
show more
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:56:05.522416 2026] [security2:error] [pid 17034:tid 17034] [client 135.129.124.216:60359] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.legalnexuslawfirm.com"] [uri "/.env"] [unique_id "aovO5Wr26UiYIEDa6Fo7QgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-24 04:35:25
(1 week ago)
287 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2026-08-24 04:19:25
(1 week ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 02:35:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink ...
show more
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:35:31.210177 2026] [security2:error] [pid 25633:tid 25648] [client 135.129.124.216:44100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.boxwoodgarden.com"] [uri "/.env"] [unique_id "aout8yDWIRS11wg9rccH0gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
almazick
2026-08-24 02:00:41
(1 week ago)
Fail2Ban jail window on srv1.windowrepair.us banned 135.129.124.216 after 1 attempts
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-24 01:53:44
(1 week ago)
[Mon Aug 24 11:53:43.267495 2026] [security2:error] [pid 54339] [client 135.129.124.216:41989] [clie ...
show more
[Mon Aug 24 11:53:43.267495 2026] [security2:error] [pid 54339] [client 135.129.124.216:41989] [client 135.129.124.216] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.env"] [unique_id "aoukJxGf9nz4bNerxAUP2QAAAAs"]
...
show less
Web App Attack
๐ณ๐ฑ
informedclearly.com
2026-08-24 01:40:04
(1 week ago)
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (X11; Linux x86_64) AppleWe ...
show more
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.env? ua=Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 01:28:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink ...
show more
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 21:27:57.443371 2026] [security2:error] [pid 7196:tid 7196] [client 135.129.124.216:39251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitality-web.com"] [uri "/.env"] [unique_id "aoueHcbfO3NUq9d9uzfEnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
simon boshoff
2026-08-24 01:22:36
(1 week ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-24 00:35:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink ...
show more
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:35:00.248364 2026] [security2:error] [pid 19703:tid 19703] [client 135.129.124.216:43395] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.homebuilt.org"] [uri "/.env"] [unique_id "aouRtNP9dKNgbCTWdDrDFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 00:26:03
(1 week ago)
Web attack blocked by Wordfence on www.museumvalkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 23:04:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink ...
show more
(mod_security) mod_security (id:210492) triggered by 135.129.124.216 (customer.lgosnga1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:04:24.782450 2026] [security2:error] [pid 21412:tid 21412] [client 135.129.124.216:10506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peggyannjones.us"] [uri "/.env"] [unique_id "aot8eNcxG2BMLGdEhHfj3QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 21:53:02
(1 week ago)
Bot / scanning and/or hacking attempts: [0/0] init, GET /.env HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
Rayulcifer
2026-08-23 19:38:32
(1 week ago)
135.129.124.216 - - [23/Aug/2026:14:38:29 -0500] "GET /.env HTTP/2.0" 403 488 "-" "Mozilla/5.0 (Maci ...
show more
135.129.124.216 - - [23/Aug/2026:14:38:29 -0500] "GET /.env HTTP/2.0" 403 488 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:148.0) Gecko/20100101 Firefox/148.0"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH