๐ฉ๐ช
yvoictra
2026-09-02 14:02:27
(9 hours ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐จ๐ฆ
Webmestre
2026-09-02 13:44:00
(9 hours ago)
Attempts against non-existent WordPress and PHP pages /backend/.env, /wp-content/.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 13:36:37
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:36:29.033391 2026] [security2:error] [pid 2533:tid 2533] [client 146.70.198.208:50808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tytiannasanderson.com"] [uri "/.env"] [unique_id "apgmXfhL_lZo7mYteQE3zAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:46:59
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:46:53.074336 2026] [security2:error] [pid 8755:tid 8755] [client 146.70.198.208:57899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twincitytn.com"] [uri "/.env"] [unique_id "apgavTHSiTOGr4d0CLSAcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:31:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:30:59.086059 2026] [security2:error] [pid 3259:tid 3277] [client 146.70.198.208:51090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tvpin.com"] [uri "/.env"] [unique_id "apgXA0yyq0IXAYWgql79vgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 12:30:02
(10 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:03:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:03:23.139149 2026] [security2:error] [pid 22476:tid 22476] [client 146.70.198.208:53565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.turtle-trap.com"] [uri "/.env"] [unique_id "apgQi28QMQ91gI-ppGTjYgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 11:50:07
(11 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 11:39:24
(11 hours ago)
146.70.198.208 - - [02/Sep/2026:13:39:18 +0200] "GET /.env HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (comp ...
show more
146.70.198.208 - - [02/Sep/2026:13:39:18 +0200] "GET /.env HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:19 +0200] "GET /.env.local HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:19 +0200] "GET /.env.production HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:20 +0200] "GET /.env.prod HTTP/1.1" 302 4607 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:20 +0200] "GET /.env.dev HTTP/1.1" 302 4609 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:20 +0200] "GET /.env.development HTTP/1.1" 302 4608 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:21 +0200] "GET /.env.staging HTTP/1.1" 302 4609 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:13:39:21 +0200] "GET /.env.backup HTTP/1.1" 302
show less
Web App Attack
Hacking
๐ณ๐ฑ
ismailk
2026-09-02 11:27:03
(11 hours ago)
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=CA puan=71 nginx=0 wf=0 cf=31 hiz ...
show more
WordPress attack on tuncayozkan.com (auto-detected): tur=imza ulke=CA puan=71 nginx=0 wf=0 cf=31 hiz=0 404cesit=0. Blocked by adaptive firewall.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 11:20:06
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:19:59.077271 2026] [security2:error] [pid 780:tid 780] [client 146.70.198.208:57080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tulsatvmemories.com"] [uri "/.env"] [unique_id "apgGX5PxirAmWFhFGC0VRQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 11:16:50
(11 hours ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 09:59:59
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:59:55.043696 2026] [security2:error] [pid 16895:tid 16895] [client 146.70.198.208:62578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.truthsabouthealthcare.com"] [uri "/.env"] [unique_id "apfzm61VYLq1BSWWkVaBEQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 09:35:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.70.198.208 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:35:26.178011 2026] [security2:error] [pid 11038:tid 11038] [client 146.70.198.208:64233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "truecontrarian.com"] [uri "/.env"] [unique_id "apft3gfJyabdFDPifQR3eAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-02 09:19:28
(13 hours ago)
146.70.198.208 - - [02/Sep/2026:05:19:25 -0400] "GET /.env HTTP/1.0" 404 360 "-" "Mozilla/5.0 (compa ...
show more
146.70.198.208 - - [02/Sep/2026:05:19:25 -0400] "GET /.env HTTP/1.0" 404 360 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:05:19:27 -0400] "GET /local/.env HTTP/1.0" 404 360 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
146.70.198.208 - - [02/Sep/2026:05:19:27 -0400] "GET /api/.env HTTP/1.0" 404 360 "-" "Mozilla/5.0 (compatible; GitScanner/2.1)"
...
show less
Web App Attack