๐บ๐ธ
antlac1
2026-10-06 17:20:41
(4 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 17:14:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 13:14:01.695127 2026] [security2:error] [pid 13588:tid 13588] [client 177.223.35.248:22974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "expertprofessionalcleaners.com"] [uri "/.env"] [unique_id "asUsWYwSCWymB27K3gf8fAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 16:44:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 12:44:08.144907 2026] [security2:error] [pid 23488:tid 23488] [client 177.223.35.248:54983] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lysedzija.com"] [uri "/.env.save"] [unique_id "asUlWE1VMYPslzZN2xEfUAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-06 14:19:54
(4 days ago)
Secret file probe | method: GET | path: /.env.production, /.env.save, /.env (+3 more) | ua: Mozilla/ ...
show more
Secret file probe | method: GET | path: /.env.production, /.env.save, /.env (+3 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-10-06 14:07:25
(4 days ago)
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env.production HTTP/1.1" 403 22241 "-" "Mozil ...
show more
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env.production HTTP/1.1" 403 22241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" edge="177.223.35.248"
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env.local HTTP/1.1" 403 22239 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" edge="177.223.35.248"
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env.prod HTTP/1.1" 403 22241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" edge="177.223.35.248"
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env.backup HTTP/1.1" 403 22241 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "-" edge="177.223.35.248"
177.223.35.248 - - [06/Oct/2026:14:06:54 +0000] "GET /.env HTTP/1.1" 403 22241
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:06:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:06:48.545334 2026] [security2:error] [pid 28584:tid 28584] [client 177.223.35.248:56501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blaslandsporthorses.com"] [uri "/.env.local"] [unique_id "asUAeArWTpW4XWhBqsdSaQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-06 13:56:02
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
etu brutus
2026-10-06 13:02:08
(4 days ago)
177.223.35.248 has been banned for [WebApp Pipeline]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:35:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:35:34.306368 2026] [security2:error] [pid 15326:tid 15326] [client 177.223.35.248:19920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garantaconsulting.com"] [uri "/.env.local"] [unique_id "asTrFoeT64k5iAoW-qlJSQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-06 12:05:19
(4 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:55:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:55:43.838484 2026] [security2:error] [pid 2749:tid 2749] [client 177.223.35.248:47010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "persnicketyinc.com"] [uri "/.env.save"] [unique_id "asThv7ZweZT-RCBOwOJ8dwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-06 07:10:03
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-06 06:58:01
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-10-06 05:05:12
(4 days ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 22:57:31
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com. ...
show more
(mod_security) mod_security (id:210492) triggered by 177.223.35.248 (177-223-35-248.linqtelecom.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 18:57:28.265529 2026] [security2:error] [pid 6836:tid 6836] [client 177.223.35.248:3830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/.env.production"] [unique_id "asQrWCzFQNLXqcJtei5DZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack