๐บ๐ธ
TPI-Abuse
2026-05-19 14:02:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 10:02:20.425589 2026] [security2:error] [pid 25047:tid 25047] [client 149.143.131.37:55655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketcityhotwheelers.com"] [uri "/.env.bak"] [unique_id "agxtbKUiHerQrYF20S2QEwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 06:43:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 02:43:15.942452 2026] [security2:error] [pid 15386:tid 15386] [client 149.143.131.37:45317] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "origenial.com"] [uri "/api/.env"] [unique_id "agq1A3sPF6EVrOQu9Ywg9gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:42:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:45.601809 2026] [security2:error] [pid 20655:tid 20677] [client 149.143.131.37:54873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinkovich.org"] [uri "/.env.yaml"] [unique_id "agbcSQS8NqowuojCS1O8fgAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:21:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:21:48.287412 2026] [security2:error] [pid 9617:tid 9617] [client 149.143.131.37:49767] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchellamazing.com"] [uri "/.env.release"] [unique_id "agbXnIm1q-STQfIZwU2GGQAAAFk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:00:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:00:26.715439 2026] [security2:error] [pid 25891:tid 25891] [client 149.143.131.37:33841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.scc1.us"] [uri "/.git/objects/"] [unique_id "agbSmgqn6Bga3ZarmWuefwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:39:59
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:36:22.622374 2026] [security2:error] [pid 32101:tid 32101] [client 149.143.131.37:33299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koshland.us"] [uri "/.env"] [unique_id "aga-5uJsv9UbtL-J2iFbVwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 10:54:38
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 06:54:28.301717 2026] [security2:error] [pid 13520:tid 13520] [client 149.143.131.37:50911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jikishin-kai.org"] [uri "/.env.uat"] [unique_id "agWp5H1YIdQgyNxpeve7GwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 09:50:01
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:49:44.000815 2026] [security2:error] [pid 14723:tid 14742] [client 149.143.131.37:54441] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.absurdotron.com"] [uri "/.env.backup"] [unique_id "agWauM4OLX7WRnBMZaEGzQAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-13 22:27:10
(4 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-13 10:05:12
(4 months ago)
Scanning/Probing (95)
Request Overload (101)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-05-13 06:50:58
(4 months ago)
2026/05/13 06:50:56 [error] 1193863#1193863: *223451185 access forbidden by rule, client: 149.143.13 ...
show more
2026/05/13 06:50:56 [error] 1193863#1193863: *223451185 access forbidden by rule, client: 149.143.131.37, server: binixo.ph, request: "GET /.env.development.local HTTP/2.0", host: "binixo.ph"
2026/05/13 06:50:57 [error] 1193863#1193863: *223451185 access forbidden by rule, client: 149.143.131.37, server: binixo.ph, request: "GET /.env.production HTTP/2.0", host: "binixo.ph"
2026/05/13 06:50:57 [error] 1193863#1193863: *223451185 access forbidden by rule, client: 149.143.131.37, server: binixo.ph, request: "GET /.env.txt HTTP/2.0", host: "binixo.ph"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 16:46:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 12:45:41.095480 2026] [security2:error] [pid 31875:tid 31875] [client 149.143.131.37:39565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yuanwei.l3l4.com"] [uri "/.git/HEAD"] [unique_id "agNZNTnOvqdKgIWagTnLtgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 13:31:19
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:30:56.903624 2026] [security2:error] [pid 10696:tid 10696] [client 149.143.131.37:60747] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lawrencehale.com"] [uri "/api/.env"] [unique_id "agMrkBxH9LT6JF2kD4GBkgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 00:29:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 20:29:04.940503 2026] [security2:error] [pid 8081:tid 8081] [client 149.143.131.37:33071] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bronislawsuchanek.com"] [uri "/.htpasswd"] [unique_id "agEi0G795zgzqgJyhMcl4AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 18:12:55
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.131.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 14:12:40.522365 2026] [security2:error] [pid 26100:tid 26100] [client 149.143.131.37:37407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jamelrobinson.com"] [uri "/.env.testing"] [unique_id "agDKmFntlNBW1y_ubehhZAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack