🇺🇸
TPI-Abuse
2026-09-13 05:37:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:37:20.834138 2026] [security2:error] [pid 13497:tid 13497] [client 159.223.180.175:54784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.athletestandard.com"] [uri "/.env"] [unique_id "aqY2kMBXehb7EUeL6nZ0HgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-09-13 01:32:14
(6 hours ago)
Brute force
Brute-Force
🇬🇧
consul.to
2026-09-12 13:18:09
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 13:16:20
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 09:16:14.894141 2026] [security2:error] [pid 22701:tid 22701] [client 159.223.180.175:52122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alosi.us"] [uri "/.env"] [unique_id "aqVQnpou3n3-wQPFw6YZ3AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:37:45
(20 hours ago)
(mod_security) mod_security (id:949110) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:37:41.385258 2026] [security2:error] [pid 1851:tid 1851] [client 159.223.180.175:40354] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "alliancegroupga.com"] [uri "/.env"] [unique_id "aqU5haPqZiPnseVOzPRNSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 09:52:09
(22 hours ago)
159.223.180.175 - - [12/Sep/2026:11:52:09 +0200] "GET /.env HTTP/1.1" 301 6604 "-" "Mozilla/5.0 (Win ...
show more
159.223.180.175 - - [12/Sep/2026:11:52:09 +0200] "GET /.env HTTP/1.1" 301 6604 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:37:00
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.180.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:36:53.569238 2026] [security2:error] [pid 25181:tid 25181] [client 159.223.180.175:33716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ags-ga.com"] [uri "/.env"] [unique_id "aqUdNX8Z0pATwTqqGuFj4AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
Olexiy Backend
2026-09-12 09:27:48
(22 hours ago)
159.223.180.175
...
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 08:58:11
(23 hours ago)
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log ...
show more
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=/.env
show less
Hacking
Web App Attack
🇫🇷
YF
2026-09-12 06:30:45
(1 day ago)
Environment file probe
Web App Attack
🇩🇪
AetherFox
2026-09-12 04:50:18
(1 day ago)
AetherFox VoidGuard detected: [Sat Sep 12 04:50:13.997358 2026] [authz_core:error] [pid 1930588:tid ...
show more
AetherFox VoidGuard detected: [Sat Sep 12 04:50:13.997358 2026] [authz_core:error] [pid 1930588:tid 1930638] [client 159.223.180.175:40120] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/
[Sat Sep 12 04:50:13.997621 2026] [authz_core:error] [pid 1930588:tid 1930638] [client 159.223.180.175:40120] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sat Sep 12 04:50:15.662783 2026] [authz_core:error] [pid 1930587:tid 1930619] [client 159.223.180.175:40126] AH01630: client denied by server configuration: proxy:https://freebeegee.draconigen.de/.env
[Sat Sep 12 04:50:15.663007 2026] [authz_core:error] [pid 1930587:tid 1930619] [client 159.223.180.175:40126] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Sat Sep 12 04:50:17.472371 2026] [authz_core:error] [pid 1930587:tid 1930621] [client 159.223.180.175:40142] AH01630: client denied by server configuration: proxy:ht
...
show less
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 01:40:50
(1 day ago)
159.223.180.175 - - [12/Sep/2026:03:40:50 +0200] "GET /.env HTTP/1.1" 404 15035 "-" "Mozilla/5.0 (Wi ...
show more
159.223.180.175 - - [12/Sep/2026:03:40:50 +0200] "GET /.env HTTP/1.1" 404 15035 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
ITSNF
2026-09-12 01:30:03
(1 day ago)
Blocked by os-abuseipdb; 11 hits, proto=tcp, ports=443
Port Scan
Hacking
🇩🇪
LRob
2026-09-11 23:58:06
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-11 23:58 UTC
show less
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-11 21:59:46
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-11
Web App Attack
SSH
Hacking