๐ป๐ณ
cimee
2026-09-25 03:48:44
(5 days ago)
This IP accessed the path /.aws/.env, which is banned.
Bad Web Bot
Web App Attack
๐ป๐ณ
cimee
2026-09-18 00:44:36
(1 week ago)
This IP accessed the path /.env.save, which is banned.
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-14 21:47:56
(1 month ago)
Web App Attack
๐บ๐ธ
mawan
2026-04-16 08:37:49
(5 months ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
4server
2026-04-05 21:49:39
(5 months ago)
[SunApr0523:49:35.2501682026][security2:error][pid2910677:tid2910782][client162.158.172.126:0]ModSec ...
show more
[SunApr0523:49:35.2501682026][security2:error][pid2910677:tid2910782][client162.158.172.126:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"98\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.maxay.ch.136-243-54-122.cpanel.site\"][uri\"/.env.old\"][unique_id\"adLY71yL95PJ2JVRX4xkGwAAANA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
webanyone
2026-03-24 22:00:52
(6 months ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-03 21:18:50
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 16:18:44.446866 2026] [security2:error] [pid 4473:tid 4473] [client 162.158.172.126:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.webuildbeaches.com"] [uri "/.git/config"] [unique_id "aadQNB7-7SY3318ItkwWdAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2025-11-26 18:11:55
(10 months ago)
26/Nov/2025:19:11:54.908505 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
26/Nov/2025:19:11:54.908505 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 162.158.172.126] ModSecurity: Warning. Pattern match "(?:^|=)\\\\\\\\s*(?:{|\\\\\\\\s*\\\\\\\\(\\\\\\\\s*|\\\\\\\\w+=(?:[^\\\\\\\\s]*|\\\\\\\\$.*|\\\\\\\\$.*|<.*|>.*|\\\\\\\\'.*\\\\\\\\'|\\\\".*\\\\")\\\\\\\\s+|!\\\\\\\\s*|\\\\\\\\$)*\\\\\\\\s*(?:'|\\\\")*(?:[\\\\\\\\?\\\\\\\\*\\\\\\\\[\\\\\\\\]\\\\\\\\(\\\\\\\\)\\\\\\\\-\\\\\\\\|+\\\\\\\\w'\\\\"\\\\\\\\./\\\\\\\\\\\\\\\\]+/)?[\\\\\\\\\\\\\\\\'\\\\"]*(?:l[\\\\\\\\\\\\\\\\'\\\\"]*(?:s(?:[\\\\\\\\\\\\\\\\'\\\\"]*(?:b[\\\\\\\\\\\\\\\\'\\\\"]*_[\\\\\\\\\\\\\\\\'\\\\"]*r[\\\\\\\\\\\\\\\\'\\\\"]*e[\\\\\\\\\\\\\\\\'\\\\"]*l[\\\\\\\\\\\\\\\\' ..." at REQUEST_COOKIES:g. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "464"] [id "932150"] [msg "Remote Command Execution: Direct Unix Command Execution"] [data "Matched Data: echo found within REQUEST_COOKIES:g: echo Sp3ctra"] [severity "CRITICAL"] [ver
...
show less
Hacking
Web App Attack
๐ง๐ช
voormedia
2025-10-27 06:31:16
(11 months ago)
Accessed trap at '/.git/config'
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-07-24 23:10:28
(1 year ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2025-06-22 15:14:06
(1 year ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-04 22:25:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 04 18:25:29.020868 2025] [security2:error] [pid 2986290:tid 2986290] [client 162.158.172.126:63062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "split.cloudex.click"] [uri "/.env"] [unique_id "aEDH2a3-WXM_qivOPkjM9AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-05 00:27:13
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 20:27:05.121172 2025] [security2:error] [pid 4051562:tid 4051562] [client 162.158.172.126:20494] [client 162.158.172.126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gibitdigital.com"] [uri "/.env"] [unique_id "aBgF2fZOn6d0-KNuBTziOQAAAAc"], referer: http://cpcalendars.gibitdigital.com//.env
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-17 12:57:26
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 17 08:57:22.204873 2025] [security2:error] [pid 25114:tid 25114] [client 162.158.172.126:47796] [client 162.158.172.126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/.env.production"] [unique_id "aAD6smPn6UbHXd-S7oiiowAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-15 15:50:08
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.172.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 15 11:50:00.487677 2025] [security2:error] [pid 9136:tid 9136] [client 162.158.172.126:23110] [client 162.158.172.126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.globetechsecurities.com"] [uri "/api/.env"] [unique_id "Z_6AKO2SU31TACsSida1_AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack