๐บ๐ธ
mnsf
2026-04-08 19:05:51
(2 months ago)
Too many Status 40X (11)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 15:47:10
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 11:46:58.602304 2026] [security2:error] [pid 215247:tid 215247] [client 172.70.175.149:10414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trlservice.com"] [uri "/.env~"] [unique_id "adPVco_CiOvu8n_ZLjTzAgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 01:26:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 21:26:42.751703 2026] [security2:error] [pid 19718:tid 19718] [client 172.70.175.149:14268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antoniorufino.com"] [uri "/.env.old"] [unique_id "adML0s0Nzxx2nIQyPmrrCgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 16:53:47
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 12:53:43.486937 2026] [security2:error] [pid 14943:tid 14943] [client 172.70.175.149:12122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.zebax.com"] [uri "/server/.env"] [unique_id "adFCF5Utq88CFNt1ZkSPkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:25:08
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:25:00.832721 2026] [security2:error] [pid 26190:tid 26190] [client 172.70.175.149:13948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.luxandunion.com"] [uri "/backend/.env"] [unique_id "adEfPGzHpOxiMp0XmaPI7QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-04 12:20:57
(2 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 08:21:16
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 04:21:08.759556 2026] [security2:error] [pid 10896:tid 10896] [client 172.70.175.149:12263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kletzer.com"] [uri "/docker/.env.local"] [unique_id "adDJ9F1qYRxcfrXmn8sjdAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 06:42:31
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:42:25.333078 2026] [security2:error] [pid 29794:tid 29794] [client 172.70.175.149:9391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.z-mgmt.com"] [uri "/.env.local.backup"] [unique_id "adCy0Tp7JHonI107vNp3tAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 02:30:02
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 22:29:54.932997 2026] [security2:error] [pid 32320:tid 32320] [client 172.70.175.149:12263] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.livegoodherbs.com"] [uri "/home/.env"] [unique_id "adB3otCU-StoAbvjwkLnxwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 15:28:49
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 11:28:41.686949 2026] [security2:error] [pid 29383:tid 29383] [client 172.70.175.149:9777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cormanleigh.com"] [uri "/.env.backup"] [unique_id "ac_cqWYmnhRvpQxslQavgwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 11:27:04
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 07:26:58.058509 2026] [security2:error] [pid 28964:tid 28975] [client 172.70.175.149:12565] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.whitecrosslibrary.com"] [uri "/core/.env"] [unique_id "ac-kAg9Y8ZGoqIDA0JPYYwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 09:58:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 05:58:10.162855 2026] [security2:error] [pid 7660:tid 7660] [client 172.70.175.149:14236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.toxicwater.com"] [uri "/config/.env"] [unique_id "ac-PMpbxS-AcZfeEUJ6O9gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-03 06:06:47
(2 months ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 14:58:58
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 10:58:49.683454 2026] [security2:error] [pid 12149:tid 12160] [client 172.70.175.149:13360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.oceanstatecollision.com"] [uri "/.env.dist"] [unique_id "ac0yqaN6euKjtJi9U-oI-gAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 14:01:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.70.175.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 10:01:14.301826 2026] [security2:error] [pid 8449:tid 8449] [client 172.70.175.149:13104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sandboxspeech.org"] [uri "/api/.env"] [unique_id "ac0lKkTH5kn5CSeU8ewzWwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack