🇺🇸
TPI-Abuse
2026-09-12 06:00:53
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:00:47.034904 2026] [security2:error] [pid 13866:tid 13866] [client 151.240.56.14:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr.com"] [uri "/.env"] [unique_id "aqTqj9_Mj7hx4XHZfVvN5AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
JaRoNL
2026-09-12 04:51:31
(1 hour ago)
151.240.56.14 - - [12/Sep/2026:06:51:30 +0200] "GET /.env HTTP/1.1" 404 49609 "-" "Mozilla/5.0 (Maci ...
show more
151.240.56.14 - - [12/Sep/2026:06:51:30 +0200] "GET /.env HTTP/1.1" 404 49609 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-12 03:47:18
(2 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
big-cloud.nl
2026-09-12 03:37:43
(2 hours ago)
Try to access /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:04:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:04:01.719172 2026] [security2:error] [pid 7712:tid 7712] [client 151.240.56.14:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodrigoaldecoa.com"] [uri "/.env"] [unique_id "aqTBIX_w4abQ6F8SAzcBqgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 01:29:31
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:29:23.620380 2026] [security2:error] [pid 5019:tid 5019] [client 151.240.56.14:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yggdrasil.org"] [uri "/.env"] [unique_id "aqSq80xq42LmqbCxSGyYqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:37:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:37:24.852120 2026] [security2:error] [pid 23006:tid 23006] [client 151.240.56.14:29049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asermaq.cl"] [uri "/.env"] [unique_id "aqSexC-iiF48uqB9CZvYUAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-11 23:54:18
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-11 23:54 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-11 23:50:44
(6 hours ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
Anonymous
2026-09-11 23:05:02
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.env HTTP/1.1
Hacking
Web App Attack
🇵🇱
nakordoni.eu
2026-09-11 23:00:05
(7 hours ago)
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matc ...
show more
Blocked by nakordoni.eu automated security: nakordoni-probe-gate. Jail: nakordoni-probe-gate, 1 matches. ISP: GSL Networks Pty LTD (US), Usage: Data Center/Web Hosting/Transit. Prior AbuseIPDB score at ban time: 91/100.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 22:43:49
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 18:43:40.802841 2026] [security2:error] [pid 6107:tid 6107] [client 151.240.56.14:64931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiofamilia.com.mx"] [uri "/.env"] [unique_id "aqSEHHypEqAIvDHGURvBJAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 21:57:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 151.240.56.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:57:40.345674 2026] [security2:error] [pid 25726:tid 25733] [client 151.240.56.14:22641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.docdalton.com"] [uri "/.env"] [unique_id "aqR5VKpG4QMOLs9EqBDCWAAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-11 21:00:37
(9 hours ago)
Environment file probe
Web App Attack
🇯🇵
ki3
2026-09-11 21:00:32
(9 hours ago)
Fail2Ban: Web App Attacks and Forum Spam 151.240.56.14 1789160432.0(JST)
Web Spam
Bad Web Bot
Web App Attack