๐บ๐ธ
mnsf
2026-08-01 03:05:34
(2 hours ago)
Scanning/Probing (34)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 02:52:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 22:52:06.905130 2026] [security2:error] [pid 1371266:tid 1371266] [client 157.66.55.189:64475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glslightingandcontrols.com"] [uri "/.env.production"] [unique_id "am1fVkxK7XmwphgHRkNmqgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 01:36:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:36:26.297710 2026] [security2:error] [pid 23843:tid 23843] [client 157.66.55.189:53947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gre-home.com"] [uri "/.env"] [unique_id "am1Nmg3N5DVJmYv0DCorbQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 01:08:51
(4 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: ID, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: ID, Attack patterns: WordPress scanning, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 01:05:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:05:37.157682 2026] [security2:error] [pid 1590332:tid 1590332] [client 157.66.55.189:65304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marlinlee.com"] [uri "/app/.env.local"] [unique_id "am1GYVnF2BFIcecGfiBsQAAAAF8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 00:38:23
(4 hours ago)
157.66.55.189 - - [31/Jul/2026:16:43:05 -0500] "GET /.env.production HTTP/1.1" 403 199 "http://sambr ...
show more
157.66.55.189 - - [31/Jul/2026:16:43:05 -0500] "GET /.env.production HTTP/1.1" 403 199 "http://sambrownlaw.com/.env.production" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 172.68.164.138
157.66.55.189 - - [31/Jul/2026:16:43:05 -0500] "GET /.env.local HTTP/1.1" 403 199 "http://sambrownlaw.com/.env.local" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 172.71.124.249
157.66.55.189 - - [31/Jul/2026:16:43:05 -0500] "GET /.env.staging HTTP/1.1" 403 199 "http://sambrownlaw.com/.env.staging" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 172.71.124.248
157.66.55.189 - - [31/Jul/2026:16:43:05 -0500] "GET /.env.development HTTP/1.1" 403 199 "http://sambrownlaw.com/.env.development" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" 172.69.165.34
157
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 00:24:34
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 20:24:25.598189 2026] [security2:error] [pid 4060889:tid 4060889] [client 157.66.55.189:64634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webjemm.net"] [uri "/app/.env.staging"] [unique_id "am08uSl0LtZhfd-UiGnHcAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-01 00:01:05
(5 hours ago)
223 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-31 23:56:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:56:07.497918 2026] [security2:error] [pid 1454879:tid 1454879] [client 157.66.55.189:49661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prcomputersolutions.com"] [uri "/.env"] [unique_id "am02F1BgmZxTRtcUOvdoKwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-31 23:50:59
(5 hours ago)
Web vulnerability probing: /phpinfo.php
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-31 23:45:01
(5 hours ago)
ModSecurity rule 949110 triggered on d865. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 23:37:27
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:37:22.702084 2026] [security2:error] [pid 416591:tid 416591] [client 157.66.55.189:60076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.env"] [unique_id "am0xspev6BmEMVpGxmvtgQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 23:12:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:11:57.492872 2026] [security2:error] [pid 31100:tid 31100] [client 157.66.55.189:64185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waggonerfinancial.com"] [uri "/api/.env.local"] [unique_id "am0rvWZHQBg03fX39nUfvAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-31 23:00:01
(6 hours ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-31 22:00:56
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 157.66.55.189 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:00:50.704082 2026] [security2:error] [pid 806835:tid 806835] [client 157.66.55.189:55209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fvsllc.com"] [uri "/config/.env.staging"] [unique_id "am0bEjcYeiEx1x2fDPYDXAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack