๐บ๐ธ
TPI-Abuse
2026-10-09 11:12:14
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:12:10.169803 2026] [security2:error] [pid 4480:tid 4480] [client 146.148.101.255:58258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiancommoditiescorporation.com"] [uri "/.env"] [unique_id "asjMCg3OTRNC0lJDuAnTGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-09 05:03:15
(18 hours ago)
(mod_security) mod_security (id:949110) triggered by 146.148.101.255 (US/United States/255.101.148.1 ...
show more
(mod_security) mod_security (id:949110) triggered by 146.148.101.255 (US/United States/255.101.148.146.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-10-09 04:22:20
(19 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ง๐ช
voormedia
2026-10-09 03:48:07
(19 hours ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:45:11
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:45:06.642517 2026] [security2:error] [pid 6136:tid 6136] [client 146.148.101.255:51041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arnoldwell.com"] [uri "/.env"] [unique_id "ashjQp7htCHyiaX-IH0HIQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 03:16:19
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 23:16:13.862150 2026] [security2:error] [pid 29918:tid 29921] [client 146.148.101.255:62723] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wpe.uk.com"] [uri "/.env"] [unique_id "ashcfS3UCAqnXBrG73B0tAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 05:28:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:28:48.354562 2026] [security2:error] [pid 7113:tid 7113] [client 146.148.101.255:58113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/.env"] [unique_id "ascqENwsCZlSupO9dUQcmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Grossmann-Gruppe
2026-10-07 16:58:44
(2 days ago)
Plesk Fail2Ban: plesk-modsecurity
Hacking
Brute-Force
๐ฉ๐ช
gadix
2026-10-07 16:40:18
(2 days ago)
[07/Oct/2026:17:04:06.466252 +0200] asZfZvqB_xw0CtuHL6eH5QAAAAA 146.148.101.255 33440 127.0.0.1 7081 ...
show more
[07/Oct/2026:17:04:06.466252 +0200] asZfZvqB_xw0CtuHL6eH5QAAAAA 146.148.101.255 33440 127.0.0.1 7081
[07/Oct/2026:18:38:09.951049 +0200] asZ1cb98GA9PIy6_fWz0bwAAAAk 146.148.101.255 55540 127.0.0.1 7081
[07/Oct/2026:18:40:17.505479 +0200] asZ18aTU8q18PAIbr9b_cwAAAAs 146.148.101.255 37298 127.0.0.1 7081
...
show less
Web App Attack
๐ง๐ช
voormedia
2026-10-07 16:36:37
(2 days ago)
Accessed trap at '/.env'
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-10-07 16:35:52
(2 days ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
LRob
2026-10-07 16:31:57
(2 days ago)
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW ...
show more
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3
show less
Hacking
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-07 15:06:07
(2 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 13:58:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 146.148.101.255 (255.101.148.146.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:57:55.946286 2026] [security2:error] [pid 3049:tid 3049] [client 146.148.101.255:50487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fashionmenswear.com"] [uri "/.env"] [unique_id "asZP44WULb69yAa7mLQBRgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack