πΊπΈ
TPI-Abuse
2026-05-20 13:44:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 09:44:26.638603 2026] [security2:error] [pid 5613:tid 5613] [client 149.143.128.193:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env.example"] [unique_id "ag26uug2haWjxFbBApP07QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-19 08:36:11
(3 months ago)
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.128.193 - - [19/May/2026:08:36:08 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [19/May/2026:08:36:08 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.128.193 - - [19/May/2026:08:36:08 +0000] "GET /xmlrpc.php HTTP/1.1"
[REDACTED] 200 2627 149.143.128.193 - - [19/May/2026:08:36:08 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 149.143.128.193 - - [19/May/2026:08:36:09 +0000] "GET /.env.old HTTP/1.1"
show less
Port Scan
π©πͺ
IVski.com
2026-05-18 09:57:27
(3 months ago)
IVski WAF | Multiple 403 Forbidden responses detected from this IP. Likely automated scanning.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 13:12:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:11:53.798868 2026] [security2:error] [pid 30835:tid 30835] [client 149.143.128.193:43559] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.island.cleanhorizons.org"] [uri "/.env.default"] [unique_id "agm-mccSymz8o4XWiMerJAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-17 08:56:18
(3 months ago)
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.128.193 - - [17/May/2026:08:56:16 +0000] "HEAD /.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [17/May/2026:08:56:16 +0000] "HEAD /root/.aws/config HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [17/May/2026:08:56:16 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [17/May/2026:08:56:17 +0000] "HEAD /.env HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [17/May/2026:08:56:17 +0000] "HEAD /.aws/credentials HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-16 05:43:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 01:42:55.618935 2026] [security2:error] [pid 32739:tid 32739] [client 149.143.128.193:46085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenmonkeyproject.com"] [uri "/.env.prod"] [unique_id "aggD316lZmacFd9CRvqWQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:57:40
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:57:29.013017 2026] [security2:error] [pid 10368:tid 10368] [client 149.143.128.193:39837] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env.sample"] [unique_id "agbf-Q6hZmdXo8FaE0gBEgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:24:33
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:24:01.652010 2026] [security2:error] [pid 13981:tid 13981] [client 149.143.128.193:56913] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnhansonmemorial.org.coolingsprings.org"] [uri "/.svn/entries"] [unique_id "agbYIQ5_fJHAADZ1q9jpLgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 08:01:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:01:25.155965 2026] [security2:error] [pid 23726:tid 23726] [client 149.143.128.193:58331] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "macro-astrology.com"] [uri "/api/.env"] [unique_id "agbS1asOwS9mR9458hOdYQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-15 07:32:00
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:31:33.441249 2026] [security2:error] [pid 31157:tid 31157] [client 149.143.128.193:35033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boens.org"] [uri "/api/.env"] [unique_id "agbL1fuBtiV4S7JnNmsVsAAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 09:47:40
(3 months ago)
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.128.193 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.128.193 - - [13/May/2026:08:48:51 +0000] "HEAD /.aws/credentials HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [13/May/2026:09:35:51 +0000] "HEAD /.env.old HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [13/May/2026:09:47:34 +0000] "HEAD /api/.env HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [13/May/2026:09:47:34 +0000] "HEAD /.env.production HTTP/1.1"
[REDACTED] 200 0 149.143.128.193 - - [13/May/2026:09:47:37 +0000] "HEAD /.git/config HTTP/1.1"
show less
Port Scan
π©πͺ
Holger
2026-05-12 23:49:00
(3 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 19:48:56
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 15:48:35.153200 2026] [security2:error] [pid 1089:tid 1089] [client 149.143.128.193:57363] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vid.com"] [uri "/.env.live"] [unique_id "agOEE66OJAks3RhLNJBYVAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 12:46:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.128.193 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:45:46.863876 2026] [security2:error] [pid 19203:tid 19203] [client 149.143.128.193:33265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheamar.com"] [uri "/.env.release"] [unique_id "agMg-lRCerOEKK1wmeFPhwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Holger
2026-05-11 09:49:49
(3 months ago)
Bruteforce WebAttack
Brute-Force
Web App Attack