๐บ๐ธ
TPI-Abuse
2026-06-01 18:41:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 14:41:32.126252 2026] [security2:error] [pid 22421:tid 22421] [client 153.92.8.48:33528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "premaindustrial.com"] [uri "/api/.env"] [unique_id "ah3SXMC9Mad68AjF3PyqrgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 17:37:34
(3 days ago)
(caddyscan) Scanner path probe from 153.92.8.48 (ID/Indonesia/srv27.niagahoster.com): 5 in the last ...
show more
(caddyscan) Scanner path probe from 153.92.8.48 (ID/Indonesia/srv27.niagahoster.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 153.92.8.48 - - [01/Jun/2026:17:37:30 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.48 - - [01/Jun/2026:17:37:30 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.48 - - [01/Jun/2026:17:37:30 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.48 - - [01/Jun/2026:17:37:30 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.48 - - [01/Jun/2026:17:37:30 +0000] "GET /backend/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-01 17:11:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 13:11:41.338894 2026] [security2:error] [pid 6624:tid 6624] [client 153.92.8.48:36308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interior-cosmetics.com"] [uri "/app/.env"] [unique_id "ah29TbrzTPO01M1xdqkSBwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 15:36:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 11:35:57.631995 2026] [security2:error] [pid 27515:tid 27515] [client 153.92.8.48:44030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "damonmarks.com"] [uri "/dev/.env"] [unique_id "ah2m3cwG9V68zPyNvUA8qQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 15:14:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 11:14:06.504122 2026] [security2:error] [pid 21926:tid 21926] [client 153.92.8.48:35094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cassandramari.com"] [uri "/app/.env"] [unique_id "ah2hvt1SGUGvH2uU5dUM3gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-01 15:12:11
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 12:21:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 08:21:13.903081 2026] [security2:error] [pid 9175:tid 9175] [client 153.92.8.48:53894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnicvpn.com"] [uri "/new/.env"] [unique_id "ah15OcA0kjk0SX5v4fm4IwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-01 12:04:04
(3 days ago)
[MonJun0114:04:02.7228132026][security2:error][pid2698878:tid2698915][client153.92.8.48:0]ModSecurit ...
show more
[MonJun0114:04:02.7228132026][security2:error][pid2698878:tid2698915][client153.92.8.48:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\b\(\?:\\\\\\\\.\(\?:ht\(\?:access\|passwd\|group\)\|www_\?acl\)\|global\\\\\\\\.asa\|httpd\\\\\\\\.conf\|boot\\\\\\\\.ini\|web.config\)\\\\\\\\b\|\(\|\^\|\\\\\\\\.\\\\\\\\.\)/etc/\|/\\\\\\\\.\(\?:history\|bash_history\|sh_history\|env\)\$\)\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"204\"][id\"390709\"][rev\"30\"][msg\"Atomicorp.comWAFRules:Attempttoaccessprotectedfileremotely\"][data\"/.env\"][severity\"CRITICAL\"][hostname\"mood4apps.com\"][uri\"/member/.env\"][unique_id\"ah11MmodsQom5PZyUPK68gAAAEE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 08:30:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 04:30:01.984193 2026] [security2:error] [pid 20401:tid 20401] [client 153.92.8.48:54216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theknowledgemaster.com"] [uri "/new/.env"] [unique_id "ah1DCf3QtPSMhyT8D6308wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 07:23:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 03:22:56.243357 2026] [security2:error] [pid 32173:tid 32173] [client 153.92.8.48:18544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cartoondelivery.com"] [uri "/api/.env"] [unique_id "ah0zUKq0y6rjohAoFtjVcgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-01 06:28:57
(3 days ago)
446 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-01 05:13:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 01:13:37.088621 2026] [security2:error] [pid 2880:tid 2880] [client 153.92.8.48:32228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "loupgaroubooks.com"] [uri "/new/.env"] [unique_id "ah0VAXY1eHj0MJ7_qk3mPwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-06-01 04:47:48
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 153.92.8.48 (ID/Indonesia/srv27.niagahoster.com ...
show more
(mod_security) mod_security (id:949110) triggered by 153.92.8.48 (ID/Indonesia/srv27.niagahoster.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:59:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.48 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:59:35.787207 2026] [security2:error] [pid 13891:tid 13891] [client 153.92.8.48:48928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rotorservice.com"] [uri "/.env"] [unique_id "ahz1l-oJiosiMt1YkHXsEgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-06-01 02:31:56
(3 days ago)
Login credentials theft attempt
Hacking