TPI-Abuse
2025-03-19 16:32:13
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 12:32:09.226171 2025] [security2:error] [pid 8068:tid 8068] [client 137.59.162.234:50828] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "savingshvac.com"] [uri "/.env"] [unique_id "Z9rxiRkwQThaTngFeS3eaAAAAA8"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-19 15:46:51
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 19 11:46:44.318712 2025] [security2:error] [pid 1513952:tid 1513952] [client 137.59.162.234:38008] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riser-astrology.com"] [uri "/.env"] [unique_id "Z9rm5BL7M8hjWk1Y0xPyXAAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-19 09:54:57
(1 day ago)
fail2ban apache-modsecurity web [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [uri "/.env ... show more fail2ban apache-modsecurity web [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [uri "/.env"] show less
Web App Attack
octageeks.com
2025-03-19 04:06:54
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
TPI-Abuse
2025-03-18 21:52:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 17:52:39.872768 2025] [security2:error] [pid 675657:tid 675657] [client 137.59.162.234:39824] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blockadegc.weyoungrenovations.com"] [uri "/.env"] [unique_id "Z9nrJ9J1vgKqneRz7oTd0AAAABU"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 21:35:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 17:35:48.085675 2025] [security2:error] [pid 11039:tid 11102] [client 137.59.162.234:47086] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.barkdullit.com.ceol.us"] [uri "/.env"] [unique_id "Z9nnNPkc1SF4oOgF-xdypQAAAIE"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 20:54:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 16:54:20.105372 2025] [security2:error] [pid 727200:tid 727200] [client 137.59.162.234:53596] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingstructural.amazingwelding.com"] [uri "/.env"] [unique_id "Z9ndfCoOS09EFWOWhmnBUQAAABo"] show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-18 20:50:04
(1 day ago)
Malicious activity detected
Hacking
Web App Attack
TPI-Abuse
2025-03-18 15:21:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 11:21:47.946958 2025] [security2:error] [pid 21553:tid 21553] [client 137.59.162.234:50164] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.canyoubuyhappiness.kmp.net"] [uri "/.env"] [unique_id "Z9mPi9Ocxwa9vtIPM8BSdQAAAAg"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 13:17:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 09:17:19.042675 2025] [security2:error] [pid 27291:tid 27291] [client 137.59.162.234:58252] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.knuf1.fritsknuf.com"] [uri "/.env"] [unique_id "Z9lyX8kEnKVSv-5EQo7ObAAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 12:39:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 08:39:23.989454 2025] [security2:error] [pid 186197:tid 186197] [client 137.59.162.234:41096] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.japanesejapan.smogsandiego.com"] [uri "/.env"] [unique_id "Z9lpe0tp6WF8SP9-phdRmwAAABA"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 11:47:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 07:47:01.828503 2025] [security2:error] [pid 30040:tid 30040] [client 137.59.162.234:56136] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hildasterncohen.williamgilcher.com"] [uri "/.env"] [unique_id "Z9ldNY_rBNiXuPN3MOg8NwAAAAQ"] show less
Brute-Force
Bad Web Bot
Web App Attack
TPI-Abuse
2025-03-18 09:43:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 ... show more (mod_security) mod_security (id:210492) triggered by 137.59.162.234 (subs-162.59.137.ski.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 05:43:09.012448 2025] [security2:error] [pid 1690:tid 1690] [client 137.59.162.234:39868] [client 137.59.162.234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nelsonprototype.blackjobsnetwork.com"] [uri "/.env"] [unique_id "Z9lALc9MHgp0USXx3-O8zwAAAAw"] show less
Brute-Force
Bad Web Bot
Web App Attack
advena
2025-03-15 18:31:12
(4 days ago)
137.59.162.234 (AS59281 SKINET-AS-ID PT Sumber Koneksi Indonesia) was intercepted at 2025-03-15T18:2 ... show more 137.59.162.234 (AS59281 SKINET-AS-ID PT Sumber Koneksi Indonesia) was intercepted at 2025-03-15T18:20:21Z after violating WAF directive: d0380eeb922844b5b69152600cea062c. Pre-cautionary/corrective action applied: block. show less
Web Spam
Hacking
Brute-Force
Web App Attack
Anonymous
2025-03-15 18:02:18
(4 days ago)
Malicious activity detected
Hacking
Web App Attack