๐บ๐ธ
TPI-Abuse
2026-06-14 04:14:56
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 00:14:52.531372 2026] [security2:error] [pid 22088:tid 22088] [client 149.40.49.4:23239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lukeschicago.com"] [uri "/.env"] [unique_id "ai4qvBijfpCOJcqdkiz7LwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 04:00:01
(5 hours ago)
Configuration snooping (/.env):
149.40.49.4 - - [14/Jun/2026:04:49:57 +0100] "GET /.env HTTP/1.1" 4 ...
show more
Configuration snooping (/.env):
149.40.49.4 - - [14/Jun/2026:04:49:57 +0100] "GET /.env HTTP/1.1" 404 241 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 03:57:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:57:11.153816 2026] [security2:error] [pid 10572:tid 10572] [client 149.40.49.4:38989] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goseethenurse.com"] [uri "/.env"] [unique_id "ai4ml2Hj0EinP3mCJ5EwIQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-06-14 03:08:09
(6 hours ago)
[redacted] 149.40.49.4 - - [14/Jun/2026:04:08:06 +0100] "GET /.env HTTP/1.1" 302 1548 0/37292 "-" "M ...
show more
[redacted] 149.40.49.4 - - [14/Jun/2026:04:08:06 +0100] "GET /.env HTTP/1.1" 302 1548 0/37292 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" [redacted] 149.40.49.4 - - [14/Jun/2026:04:08:07 +0100] "GET /sendgrid/.env HTTP/1.1" 302 1548 0/38086 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 02:47:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:47:14.168409 2026] [security2:error] [pid 28793:tid 28793] [client 149.40.49.4:19080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "encoremtmorris.com"] [uri "/.env"] [unique_id "ai4WMkAM2S5lUXQS29pJFAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Jim Keir
2026-06-14 02:46:52
(6 hours ago)
2026-06-14 02:46:52 149.40.49.4 File scanning, blocking 149.40.49.4 for 5 minutes
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 02:32:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:32:01.710878 2026] [security2:error] [pid 8472:tid 8472] [client 149.40.49.4:44914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lowkeytiki.com"] [uri "/.env"] [unique_id "ai4SoTG-ukKobVtlrS6CbwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-06-14 02:30:01
(7 hours ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ฉ๐ช
4server
2026-06-14 01:46:58
(7 hours ago)
[SunJun1403:46:52.5466052026][security2:error][pid1981774:tid1981860][client149.40.49.4:0]ModSecurit ...
show more
[SunJun1403:46:52.5466052026][security2:error][pid1981774:tid1981860][client149.40.49.4:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"www.casaplusticino.ch\"][uri\"/sendgrid/.env\"][unique_id\"ai4IDDZ8drWC31p_WORqOQAAAJY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:29:30
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:29:23.656794 2026] [security2:error] [pid 23306:tid 23306] [client 149.40.49.4:57667] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/.env"] [unique_id "ai4D82vq6Jhh2KKOdVnDggAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:05:10
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:05:04.649420 2026] [security2:error] [pid 479:tid 479] [client 149.40.49.4:55582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildlifetaxidermy.com"] [uri "/.env"] [unique_id "ai3-QEHHY9h3WGE5c-adoQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 01:05:07
(8 hours ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 00:49:37
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.40.49.4 (srv57909656.ultasrv.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 20:49:31.775973 2026] [security2:error] [pid 25433:tid 25460] [client 149.40.49.4:47675] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fishrapper.com"] [uri "/.env"] [unique_id "ai36m0XPUzX5erbVvLB4iwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-06-14 00:33:33
(9 hours ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-14 00:32:54
(9 hours ago)
149.40.49.4 - - [14/Jun/2026:03:32:54 +0300] "GET /.env HTTP/1.1" 404 762 "-" "Mozilla/5.0 (X11; Lin ...
show more
149.40.49.4 - - [14/Jun/2026:03:32:54 +0300] "GET /.env HTTP/1.1" 404 762 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack