Anonymous
2026-06-07 17:00:34
(23 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-06-05 09:59:40
(3 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
oncord
2026-05-21 20:13:10
(2 weeks ago)
Form spam
Web Spam
๐ฉ๐ช
FeG Deutschland
2026-04-23 00:53:05
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-20 19:12:08
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
mawan
2026-03-30 22:57:08
(2 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 03:10:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 23:10:12.339593 2026] [security2:error] [pid 27531:tid 27531] [client 162.158.159.153:9383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.skintormint.com"] [uri "/.env.local.backup"] [unique_id "ab4MFKt18xxJVaHfJbQ4ugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:19:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:19:04.932675 2026] [security2:error] [pid 24811:tid 24811] [client 162.158.159.153:14026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clinicadentaldiaz.aticom.es"] [uri "/.env.production"] [unique_id "ab3yCAZToR0ss-_5SgQPGAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 00:09:24
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 20:09:18.484675 2026] [security2:error] [pid 17052:tid 17052] [client 162.158.159.153:12016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.businessvaluationapp.com"] [uri "/private/.env"] [unique_id "ab3hrlhiaSxdgwchX5DgNAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2026-03-20 06:30:12
(2 months ago)
2026/03/20 06:30:06 [error] 2491776#2491776: *166275 access forbidden by rule, client: 162.158.159.1 ...
show more
2026/03/20 06:30:06 [error] 2491776#2491776: *166275 access forbidden by rule, client: 162.158.159.153, server: staging-api.bridginggaps.tech, request: "GET /.env.tmp HTTP/2.0", host: "staging-api.bridginggaps.tech"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:40:46
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:40:41.283961 2026] [security2:error] [pid 23037:tid 23046] [client 162.158.159.153:10440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vancekelly.com"] [uri "/.env.backup"] [unique_id "abzBudnFF9Wl_vy7aoF75QAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 02:03:00
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 22:02:54.054755 2026] [security2:error] [pid 31158:tid 31158] [client 162.158.159.153:13220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realtorpaul.com"] [uri "/.env.json"] [unique_id "abyqzudYOlCTSml1GI8gwQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:42:38
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:42:24.765032 2026] [security2:error] [pid 24790:tid 24827] [client 162.158.159.153:12391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaelaccounting.antidote-it.com"] [uri "/.env.example"] [unique_id "abvhIKC5pY2lcVO9iI3ZdAAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:07:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:07:27.826239 2026] [security2:error] [pid 19428:tid 19428] [client 162.158.159.153:9890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cthog.xyz"] [uri "/.envrc"] [unique_id "abvY79QcRu8i2k2n_qDVQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 10:33:02
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.159.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 06:32:57.189299 2026] [security2:error] [pid 28044:tid 28044] [client 162.158.159.153:9616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.circleinthesquare.org"] [uri "/.env.prod"] [unique_id "abvQ2YRIfQ5q2VR3Zsx0OwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack