๐ฉ๐ช
LRob
2026-06-07 20:30:09
(2 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ณ๐ฑ
e.fierstra
2026-06-07 19:06:31
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 18:36:48
(2 months ago)
(caddyscan) Scanner path probe from 153.92.8.8 (ID/Indonesia/srv27.niagahoster.com): 5 in the last 3 ...
show more
(caddyscan) Scanner path probe from 153.92.8.8 (ID/Indonesia/srv27.niagahoster.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:18:36:45 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:18:36:45 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:18:36:45 +0000] "GET /api/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:18:36:45 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:18:36:45 +0000] "GET /core/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-07 11:24:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 07:24:35.391264 2026] [security2:error] [pid 6224:tid 6224] [client 153.92.8.8:47146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laura-stone.com"] [uri "/backend/.env"] [unique_id "aiVU883scvOCfGLFskrSrwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 08:33:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 04:33:27.380876 2026] [security2:error] [pid 25290:tid 25290] [client 153.92.8.8:39012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twilighthackers.com"] [uri "/api/.env"] [unique_id "aiUs17yS0QqUWlrkkN8hsgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 07:30:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 03:30:20.024550 2026] [security2:error] [pid 376:tid 376] [client 153.92.8.8:33872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sonajstarplanet.com"] [uri "/admin/.env"] [unique_id "aiUeDOj1aOhQsDAxOYJifAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-07 07:11:21
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-06-07 06:29:03
(2 months ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:55:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:55:24.420430 2026] [security2:error] [pid 19258:tid 19258] [client 153.92.8.8:54536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tttns.com"] [uri "/admin/.env"] [unique_id "aiUHzG8lFUEzBniv11mEUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-07 05:41:13
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:14:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:14:07.901581 2026] [security2:error] [pid 7238:tid 7238] [client 153.92.8.8:60336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphabravocharters.com"] [uri "/new/.env"] [unique_id "aiT-H7Ub5cwmgEr0baWhWgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 02:21:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 22:21:38.073431 2026] [security2:error] [pid 28447:tid 28447] [client 153.92.8.8:44758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ridgecrestconsultinggroup.com"] [uri "/new/.env"] [unique_id "aiTVssaRMrb4tlk_Kwlj-QAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 01:56:02
(2 months ago)
(caddyscan) Scanner path probe from 153.92.8.8 (ID/Indonesia/srv27.niagahoster.com): 5 in the last 3 ...
show more
(caddyscan) Scanner path probe from 153.92.8.8 (ID/Indonesia/srv27.niagahoster.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:01:56:01 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:01:56:01 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:01:56:01 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:01:56:01 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 153.92.8.8 - - [07/Jun/2026:01:56:01 +0000] "GET /app/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-07 01:53:59
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the la ...
show more
(mod_security) mod_security (id:210492) triggered by 153.92.8.8 (srv27.niagahoster.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 21:53:52.830156 2026] [security2:error] [pid 2828:tid 2828] [client 153.92.8.8:34388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ridefilmsinc.com"] [uri "/member/.env"] [unique_id "aiTPMPUtiXMAuo6JYMIPDgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sdos.es
2026-06-07 01:11:58
(2 months ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /bank/.env"
Web App Attack