๐ฉ๐ช
electra
2026-07-10 14:04:45
(1 week ago)
Attempted to access path /.env.backup (GET request)
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-06-21 13:50:30
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
Anonymous
2026-05-26 08:14:15
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
mnsf
2026-04-09 00:05:18
(3 months ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 23:05:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 19:04:56.995890 2026] [security2:error] [pid 13387:tid 13387] [client 172.70.111.41:13582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tudor-harris.com"] [uri "/.env.bak"] [unique_id "acmwGGuZq2WI0t23GXrw6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-03-27 07:31:48
(3 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 04:00:52
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 21 00:00:46.533207 2026] [security2:error] [pid 21453:tid 21453] [client 172.70.111.41:14021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paleopathologist.com"] [uri "/private/.env"] [unique_id "ab4X7ssykt6YCpV3eFy68QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-21 01:40:29
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 21:40:23.746596 2026] [security2:error] [pid 20165:tid 20165] [client 172.70.111.41:10238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldbackup.myomni.us"] [uri "/.env.bak"] [unique_id "ab33B45gkD7vCW_ihzfziAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 07:10:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 03:10:42.511180 2026] [security2:error] [pid 32392:tid 32392] [client 172.70.111.41:11208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.slusarczyk.com"] [uri "/.env.save"] [unique_id "abzy8tQMm-mwwlDAExnxCwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 06:10:47
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 02:10:41.945982 2026] [security2:error] [pid 25148:tid 25148] [client 172.70.111.41:12903] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greed.wisk.org"] [uri "/.env1"] [unique_id "abzk4X8wLUbHx9A3vDJImwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 04:42:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 20 00:42:54.912124 2026] [security2:error] [pid 5686:tid 5686] [client 172.70.111.41:12644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iconbizpromo.com"] [uri "/site/.env"] [unique_id "abzQTtshbQVcTQkuOffShAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 03:28:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 23:28:08.446733 2026] [security2:error] [pid 13335:tid 13335] [client 172.70.111.41:13212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.xcarsubscription.com"] [uri "/.envrc"] [unique_id "aby-yKyeo9VKsb38Qf2SmwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 01:07:43
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 21:07:38.823779 2026] [security2:error] [pid 14510:tid 14510] [client 172.70.111.41:12896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penjoki.us"] [uri "/.env.local"] [unique_id "abyd2vPL9O77D53yokDs-AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-20 00:27:02
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 20:26:55.171868 2026] [security2:error] [pid 6682:tid 6682] [client 172.70.111.41:12634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.radicalchange.org"] [uri "/.env~"] [unique_id "abyUTzCvlfoeeIIZ3LSosgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-19 11:54:33
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.111.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 19 07:54:17.834380 2026] [security2:error] [pid 19391:tid 19391] [client 172.70.111.41:11409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.tomweston.net"] [uri "/.env.json"] [unique_id "abvj6bMtJKVIW44tRDT4FAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack