Anonymous
2026-09-13 13:48:15
(14 hours ago)
[osotir.org] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.env
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:50:43
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:50:36.066322 2026] [security2:error] [pid 13697:tid 13697] [client 172.104.135.228:52534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/.env"] [unique_id "aqZj3K5z7YGFdJhYIKEmJAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Lino Project
2026-09-13 07:44:36
(20 hours ago)
172.104.135.228 - - [13/Sep/2026:09:44:33 +0200] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (X11; ...
show more
172.104.135.228 - - [13/Sep/2026:09:44:33 +0200] "GET /.env HTTP/1.1" 404 397 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 07:21:42
(20 hours ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 06:48:18
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:48:11.719504 2026] [security2:error] [pid 8224:tid 8224] [client 172.104.135.228:62465] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.50"] [uri "/.env"] [unique_id "aqZHK6MFGJOkhdWRM_u1UwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 02:20:30
(1 day ago)
Sensitive Configuration File Disclosure.
Hacking
🇦🇺
FireGuard Server
2026-09-13 01:55:22
(1 day ago)
Blocked by os-abuseipdb; 3 hits, proto=tcp, ports=443
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-13 01:48:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 21:48:34.189037 2026] [security2:error] [pid 7062:tid 7062] [client 172.104.135.228:62724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.15"] [uri "/.env"] [unique_id "aqYA8hw3kVAjCFyBkh4aUwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:39:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:39:23.203416 2026] [security2:error] [pid 21434:tid 21434] [client 172.104.135.228:63235] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.142"] [uri "/.env"] [unique_id "aqXwu-curTXmFI2YBG7MnQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 00:17:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 20:17:08.106353 2026] [security2:error] [pid 19382:tid 19406] [client 172.104.135.228:64035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.123"] [uri "/.env"] [unique_id "aqXrhOvE2zd1z-eyTiHAVQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 23:14:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 19:14:19.313714 2026] [security2:error] [pid 22662:tid 22662] [client 172.104.135.228:52623] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.118"] [uri "/.env"] [unique_id "aqXcy5WcG43a6DNlppRG-wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 20:05:21
(1 day ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.env | ua: Mozilla/5.0 (X11; L ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.env | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | 2026-09-12 20:05 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 18:25:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.104.135.228 (172-104-135-228.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:25:34.162695 2026] [security2:error] [pid 29452:tid 29452] [client 172.104.135.228:49435] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.63"] [uri "/.env"] [unique_id "aqWZHlChPUuKeKxCenT2LQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-12 18:10:46
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
Hacking
Bad Web Bot
🇳🇴
jad-abuse
2026-09-12 18:05:29
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack