๐ฌ๐ง
AvonleaConsulting
2026-08-21 22:58:40
(3 hours ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 22:43:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 18:43:51.708585 2026] [security2:error] [pid 604:tid 604] [client 161.178.138.165:64685] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/.env"] [unique_id "aojUpxrzFF0S1TM0e9htBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:47:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:47:05.091805 2026] [security2:error] [pid 27122:tid 27122] [client 161.178.138.165:63195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mavikalem.org"] [uri "/.env"] [unique_id "aojHWaM1cujEZ5NU3AHjlgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-08-21 20:48:21
(5 hours ago)
vulnerability scan
Web App Attack
Anonymous
2026-08-21 20:35:15
(5 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-08-21 20:20:20
(5 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 19:57:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:57:23.085119 2026] [security2:error] [pid 17070:tid 17070] [client 161.178.138.165:64229] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modmove.com"] [uri "/.env"] [unique_id "aoito5yv4h0oh7J9gSnokgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 19:57:02
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/2.0
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-08-21 19:54:24
(6 hours ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 ( ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Action: block Source: firewallManaged ASN Description: Amazon.com, Inc. Country: US Method: GET Timestamp: 2026-08-21T19:54:24Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-08-21 19:35:03
(6 hours ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-08-21 19:26:52
(6 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-21 19:23:30
(6 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 19:10:19
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:10:15.291448 2026] [security2:error] [pid 15852:tid 15852] [client 161.178.138.165:53505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atticlodgeoutdoorlearningcenter.com"] [uri "/.env"] [unique_id "aoiil7b6POQDI2uw6wWxwwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ddw
2026-08-21 19:05:39
(6 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 17:45:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 161.178.138.165 (ec2-161-178-138-165.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:44:56.105975 2026] [security2:error] [pid 29664:tid 29664] [client 161.178.138.165:63320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feaverslane.com"] [uri "/.env"] [unique_id "aoiOmMiZJuYX1j21egkZmQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack