๐ง๐ช
taivas.nl
2026-06-22 04:33:07
(14 hours ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2026-06-21 04:32:08
(1 day ago)
Bad_requests
Bad Web Bot
Anonymous
2026-06-20 19:06:05
(2 days ago)
Trying to access config files
Web App Attack
๐จ๐ญ
4server
2026-06-20 18:48:54
(2 days ago)
[SatJun2020:48:49.7455072026][security2:error][pid1324723:tid1324808][client168.144.136.72:0]ModSecu ...
show more
[SatJun2020:48:49.7455072026][security2:error][pid1324723:tid1324808][client168.144.136.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"whatsdecor.ch\"][uri\"/.env\"][unique_id\"ajbgkYxSwpHheTjCmLTxZgAAAJY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:54:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:54:32.894627 2026] [security2:error] [pid 23441:tid 23462] [client 168.144.136.72:60931] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "uoexpanse.com"] [uri "/.env"] [unique_id "ajZVSMQgws7hexBXVJ5v-AAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
fortypoundhead
2026-06-20 07:41:11
(2 days ago)
Banned IP Address
Hacking
Web App Attack
๐ญ๐บ
bcsaba
2026-06-20 07:37:05
(2 days ago)
Probing for .env file:
168.144.136.72 - - [20/Jun/2026:09:37:03 +0200] "GET /.env HTTP/2.0" 403 146 ...
show more
Probing for .env file:
168.144.136.72 - - [20/Jun/2026:09:37:03 +0200] "GET /.env HTTP/2.0" 403 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:148.0) Gecko/20100101 Firefox/148.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:13:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:13:46.825213 2026] [security2:error] [pid 2048:tid 2048] [client 168.144.136.72:58826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elfinforest.net"] [uri "/.env"] [unique_id "ajXbOt_bgiHz-gX1Iv_rrQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-19 22:15:05
(2 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-19 17:59:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 13:59:43.770850 2026] [security2:error] [pid 30480:tid 30480] [client 168.144.136.72:65296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madrigalscripts.com"] [uri "/.env"] [unique_id "ajWDj7mrECrZiikWcqOScQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
VXG-NET
2026-06-19 15:22:14
(3 days ago)
port=80, indicator_type=info-leak
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-19 13:22:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.136.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 09:22:48.251734 2026] [security2:error] [pid 3339:tid 3339] [client 168.144.136.72:56193] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "old.renju.net"] [uri "/.env"] [unique_id "ajVCqF0bO2sJAT2km5F1BgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 18:40:02
(1 week ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Web App Attack
Hacking
SQL Injection