Anonymous
2026-05-18 15:52:33
(3 months ago)
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.137.20 - - [18/May/2026:15:24:05 +0000] "GET /.env.json HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [18/May/2026:15:24:05 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [18/May/2026:15:24:05 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [18/May/2026:15:24:18 +0000] "GET /.env.txt HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [18/May/2026:15:52:30 +0000] "GET /.env.txt HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-16 06:27:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 02:27:20.140930 2026] [security2:error] [pid 16072:tid 16072] [client 149.143.137.20:52003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alextra.org"] [uri "/.env.preview"] [unique_id "aggOSHgvs1xRI2-jnJlKkwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:42:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:41:43.570611 2026] [security2:error] [pid 17846:tid 17905] [client 149.143.137.20:56827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.org"] [uri "/.env.local"] [unique_id "agbcR5QAhsgpo0NO44AwhgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:24:41
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:23:41.075462 2026] [security2:error] [pid 17997:tid 17997] [client 149.143.137.20:36029] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnhansonmemorial.org"] [uri "/.env.staging"] [unique_id "agbYDSSGrz8PiEta7SByJwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:32:20
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:31:31.865718 2026] [security2:error] [pid 28275:tid 28275] [client 149.143.137.20:36163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.sympalais.com"] [uri "/.git/config"] [unique_id "agbL063AAvBPtoJ-vd2FLQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:42:05
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:41:16.486130 2026] [security2:error] [pid 23204:tid 23204] [client 149.143.137.20:33763] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gods-law.com"] [uri "/.env~"] [unique_id "agbADCI7_DJt9-RB2VsadQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 07:51:57
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 03:51:39.963205 2026] [security2:error] [pid 14677:tid 14677] [client 149.143.137.20:45479] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchtop.com"] [uri "/.env.old"] [unique_id "agQtixkCW-anwbWfT5D_wgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 05:33:24
(4 months ago)
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.137.20 - - [13/May/2026:04:46:20 +0000] "GET /.env.default HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [13/May/2026:04:46:24 +0000] "GET /.env.render HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [13/May/2026:05:33:08 +0000] "GET /.DS_Store HTTP/1.1"
[REDACTED] 200 0 149.143.137.20 - - [13/May/2026:05:33:19 +0000] "HEAD /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [13/May/2026:05:33:19 +0000] "GET /.env.dev HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 20:37:42
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 16:37:29.731920 2026] [security2:error] [pid 13988:tid 13988] [client 149.143.137.20:60909] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||urie.to.daveewalker.bz|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "urie.to.daveewalker.bz"] [uri "/db.sql"] [unique_id "agOPiVPbtRU6pNI0IQCr3wAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 12:46:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 08:45:44.654894 2026] [security2:error] [pid 17527:tid 17527] [client 149.143.137.20:57235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheamar.com"] [uri "/.env"] [unique_id "agMg-IGi3mtyfswJYAurCgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-05-12 12:10:15
(4 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
Anonymous
2026-05-11 01:29:34
(4 months ago)
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.137.20 - - [11/May/2026:01:15:05 +0000] "HEAD /.env.production HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [11/May/2026:01:15:07 +0000] "GET /app/.DS_Store HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [11/May/2026:01:15:10 +0000] "GET /.env.cfg HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [11/May/2026:01:29:12 +0000] "GET /.env.dist HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [11/May/2026:01:29:31 +0000] "GET /.env.aws HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-10 21:13:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.137.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 17:13:03.780025 2026] [security2:error] [pid 5576:tid 5576] [client 149.143.137.20:40373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedieselgroupllc.com"] [uri "/.hg/store"] [unique_id "agD0329RmuFRkgTBvAROHAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 13:44:14
(4 months ago)
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 149.143.137.20 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.137.20 - - [09/May/2026:12:48:03 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [09/May/2026:13:44:00 +0000] "GET /.env.orig HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [09/May/2026:13:44:11 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 149.143.137.20 - - [09/May/2026:13:44:11 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 0 149.143.137.20 - - [09/May/2026:13:44:12 +0000] "HEAD /.env-example HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 06:20:10
(4 months ago)
suspicious request in access.log
Web App Attack