๐บ๐ธ
TPI-Abuse
2026-10-06 21:06:49
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:06:42.130846 2026] [security2:error] [pid 32615:tid 32637] [client 172.94.9.44:52447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "potterpuppetpals.com"] [uri "/.env"] [unique_id "asVi4oYYcDsPdW7pJEpG0QAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:34:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:33:58.870544 2026] [security2:error] [pid 11568:tid 11568] [client 172.94.9.44:57638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruisingforsex.com"] [uri "/.env"] [unique_id "asVbNrqfAo8SN27O_G9JSwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 19:55:16
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-06 19:51:45
(1 hour ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:32:37
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:32:29.451169 2026] [security2:error] [pid 16201:tid 16201] [client 172.94.9.44:60901] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marveldirectory.com"] [uri "/.env"] [unique_id "asUwrU9G9qzak6wsgwnvxwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-06 17:15:45
(4 hours ago)
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537. ...
show more
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:14:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:14:09.772351 2026] [security2:error] [pid 10663:tid 10663] [client 172.94.9.44:59352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salsberggroup.com"] [uri "/.env"] [unique_id "asUsYeFZmC4hpSDdz5WLWgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
securejdprop
2026-10-06 17:12:25
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus D ...
show more
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET DROP Spamhaus DROP Listed Traffic Inbound group 36).
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:49:03
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:48:57.857491 2026] [security2:error] [pid 25757:tid 25757] [client 172.94.9.44:61149] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "learningbyshipping.com"] [uri "/.env"] [unique_id "asUmeTKJ_g2FPvIYxTAvdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 15:39:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 11:39:05.156861 2026] [security2:error] [pid 17133:tid 17133] [client 172.94.9.44:54214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.env"] [unique_id "asUWGRmEk1vjzIixwVs_jgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-10-06 14:34:11
(7 hours ago)
WebAttack or semilar from 172.94.9.44
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-10-06 11:07:46
(10 hours ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 07:37:35
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 172.94.9.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:37:29.763992 2026] [security2:error] [pid 8551:tid 8551] [client 172.94.9.44:54877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kln.ne.jp"] [uri "/.env"] [unique_id "asSlOav635HIg-j_p8GqQwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-10-06 02:16:51
(19 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-10-06 02:07:00
(19 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
DE/Germany/-
Web App Attack