๐บ๐ธ
TPI-Abuse
2026-07-28 14:24:54
(10 minutes ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 10:24:41.550743 2026] [security2:error] [pid 1532183:tid 1532183] [client 163.7.13.2:33154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.timeless-supercars.com"] [uri "/.env.dev"] [unique_id "ami7qSSzHesMlA70rIit9QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hidemail.app
2026-07-28 14:09:45
(26 minutes ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
Anonymous
2026-07-28 14:04:57
(30 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:57:16
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:57:11.686754 2026] [security2:error] [pid 3175127:tid 3175127] [client 163.7.13.2:49834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.brmccarpentry.com"] [uri "/.env.staging"] [unique_id "ami1N_8ywn3QdHRb7iEulwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
RHNoah
2026-07-28 13:55:53
(39 minutes ago)
(htpasswd) Failed web page login from 163.7.13.2 (ID/-/-): 5 in the last 3600 secs; Ports: *; Direct ...
show more
(htpasswd) Failed web page login from 163.7.13.2 (ID/-/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_HTACCESS; Logs: [Tue Jul 28 08:58:15.525598 2026] [auth_basic:error] [pid 2120522:tid 2120651] [client 163.7.13.2:58802] AH01618: user admin not found: /server-status
[Tue Jul 28 08:58:16.994422 2026] [auth_basic:error] [pid 2120522:tid 2120606] [client 163.7.13.2:60312] AH01618: user admin not found: /server-status
[Tue Jul 28 09:04:41.023516 2026] [auth_basic:error] [pid 2120522:tid 2120634] [client 163.7.13.2:46026] AH01618: user admin not found: /server-status
[Tue Jul 28 09:04:42.047850 2026] [auth_basic:error] [pid 2120522:tid 2120641] [client 163.7.13.2:46074] AH01618: user admin not found: /server-status
[Tue Jul 28 09:55:45.274625 2026] [auth_basic:error] [pid 2759118:tid 2759268] [client 163.7.13.2:43560] AH01618: user admin not found: /server-status
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-28 13:14:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:14:11.520601 2026] [security2:error] [pid 820306:tid 820306] [client 163.7.13.2:40388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mightyquick.com"] [uri "/.env.save"] [unique_id "amirI7fu5cpEhQoS8lr86wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 12:28:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:28:23.947880 2026] [security2:error] [pid 988688:tid 988688] [client 163.7.13.2:47398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virginiatouchatruck.com"] [uri "/.env.docker.local"] [unique_id "amigZ-pE68pQq7lGTjursAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-28 12:16:08
(2 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /.env.php /.php /env/.env /config/.env ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /.env.php /.php /env/.env /config/.env ...
show less
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-07-28 12:16:07
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-07-28 12:00:14
(2 hours ago)
Automated vulnerability scanning and sensitive file probing against a secured web server. Attempted ...
show more
Automated vulnerability scanning and sensitive file probing against a secured web server. Attempted access to sensitive configuration files and common vulnerability paths.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 11:52:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:51:53.395506 2026] [security2:error] [pid 2608945:tid 2608945] [client 163.7.13.2:54894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.oceancastles.com"] [uri "/api/.env"] [unique_id "amiX2VN35p1__wDg3YE0gwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 11:33:51
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:33:34.702543 2026] [security2:error] [pid 706989:tid 706989] [client 163.7.13.2:58082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.quickwink.com|F|2"] [data ".env.conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.quickwink.com"] [uri "/.env.conf"] [unique_id "amiTjoTaBnNTHxyjGeeUPwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 11:02:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:01:48.936380 2026] [security2:error] [pid 3732765:tid 3732765] [client 163.7.13.2:35452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipspsaexchange.com"] [uri "/.env"] [unique_id "amiMHMsPmcElG2vo4fxA3AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:26:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 163.7.13.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:26:00.352460 2026] [security2:error] [pid 404415:tid 404511] [client 163.7.13.2:36052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oxfordlawschool.com"] [uri "/app/.env"] [unique_id "amiDuA4D9xCQppa9GGloAQAAAhg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mashamal
2026-07-28 10:14:54
(4 hours ago)
Vulnerability Probe
...
Web App Attack