๐บ๐ธ
TPI-Abuse
2026-07-30 20:02:17
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 16:02:12.004541 2026] [security2:error] [pid 1890062:tid 1890062] [client 157.15.65.125:51058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.smartradios.info"] [uri "/.env"] [unique_id "amutxCBewzsp1JT7mPLRrQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 19:43:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 15:43:00.983261 2026] [security2:error] [pid 2010660:tid 2010660] [client 157.15.65.125:39862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.oss-in-atm.info"] [uri "/.env"] [unique_id "amupRN4wD3_sVQGi2B_qtwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 19:25:06
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 15:25:01.519215 2026] [security2:error] [pid 1755988:tid 1755988] [client 157.15.65.125:53458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.livesteamtracks.info"] [uri "/.env"] [unique_id "amulDTjqCz_YRK6qYQYEZwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 19:08:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 15:08:18.187682 2026] [security2:error] [pid 941706:tid 941706] [client 157.15.65.125:53416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hiddenhistory.info"] [uri "/.env"] [unique_id "amuhIjADrjsXiDnF4m_BuAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 18:48:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 14:48:31.565684 2026] [security2:error] [pid 1944481:tid 1944481] [client 157.15.65.125:41026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.diamenty.info"] [uri "/.env"] [unique_id "amucfx7GNnVlOKLRgO38ygAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
abuseiphack
2026-07-30 16:56:01
(6 hours ago)
Automatic report for brute force attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:34:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:34:29.197674 2026] [security2:error] [pid 2018074:tid 2018074] [client 157.15.65.125:50716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mispar.consulting"] [uri "/.env"] [unique_id "amt9FeRrI0FrP9B_6gOSEAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 09:38:01
(13 hours ago)
Configuration snooping (/.env):
157.15.65.125 - - [30/Jul/2026:10:38:00 +0100] "GET /.env HTTP/1.1" ...
show more
Configuration snooping (/.env):
157.15.65.125 - - [30/Jul/2026:10:38:00 +0100] "GET /.env HTTP/1.1" 200 234 "https://[sub domain]/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 08:19:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 04:18:57.513813 2026] [security2:error] [pid 2984888:tid 2984888] [client 157.15.65.125:43044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.maggiemusic.ca"] [uri "/.env"] [unique_id "amm3cZQEl6drR5f8IGH1MQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 07:45:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 03:45:01.281526 2026] [security2:error] [pid 3113145:tid 3113145] [client 157.15.65.125:52616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.belmontsprings.ca"] [uri "/.env"] [unique_id "ammvfd5Y0xyRIckmS7_RoAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-07-29 06:47:08
(1 day ago)
Abivia WAF trigger: Rule scriptKiddies: Dot file access. uri: /.env
Hacking
๐จ๐ฆ
internetworld
2026-07-29 06:27:18
(1 day ago)
157.15.65.125 - - [29/Jul/2026:06:27:17 +0000] "GET /.env HTTP/1.1" 200 326 "-" "Mozilla/5.0 (Window ...
show more
157.15.65.125 - - [29/Jul/2026:06:27:17 +0000] "GET /.env HTTP/1.1" 200 326 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/138.0.0.0 Safari/537.36 Edg/138.0.0.0"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-01 04:37:21
(4 weeks ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ฉ๐ช
Viveronese
2026-06-13 03:01:43
(1 month ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 01:47:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 157.15.65.125 (ip-15.65-125.cynetindo.co.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 21:47:03.631771 2026] [security2:error] [pid 29766:tid 29766] [client 157.15.65.125:59842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/.env"] [unique_id "aiy2lzBzGjErgAYUpHJEvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack