🇺🇸
TPI-Abuse
2026-09-12 11:52:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:52:21.551236 2026] [security2:error] [pid 18418:tid 18418] [client 185.113.140.131:58003] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.116"] [uri "/.env"] [unique_id "aqU89T4_dxLQlle5x5B_LgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
donarev419
2026-09-12 11:28:49
(10 hours ago)
Connection to port 80 with data transfer.
Data preview: GET /.env HTTP/1.1
Host: 198.23.188.201
Us ...
show more
Connection to port 80 with data transfer.
Data preview: GET /.env HTTP/1.1
Host: 198.23.188.201
User-agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/53
show less
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-12 11:25:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:25:28.778223 2026] [security2:error] [pid 9881:tid 9881] [client 185.113.140.131:54298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.28"] [uri "/.env"] [unique_id "aqU2qOd4eA7cXkV8WRZzfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:06:20
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:06:14.209949 2026] [security2:error] [pid 32500:tid 32500] [client 185.113.140.131:61683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.53"] [uri "/.env"] [unique_id "aqUyJl1GsTCRF57WfyWwMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-12 11:03:53
(10 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:48:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:48:06.705255 2026] [security2:error] [pid 30853:tid 30853] [client 185.113.140.131:53484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.248"] [uri "/.env"] [unique_id "aqUt5pnXqhhDzTWzODUxLwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:08:58
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:08:53.171858 2026] [security2:error] [pid 12423:tid 12423] [client 185.113.140.131:57261] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.234"] [uri "/.env"] [unique_id "aqUktRR3uT1ha57KX0YFcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:45:58
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:45:54.844667 2026] [security2:error] [pid 12717:tid 12717] [client 185.113.140.131:53163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.137"] [uri "/.env"] [unique_id "aqUfUs6YK_9YoJdRSP2UgAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 09:36:26
(12 hours ago)
185.113.140.131 - - [12/Sep/2026:09:36:26 +0000] "GET /.env HTTP/1.1" 404 6852 "-" "Mozilla/5.0 (X11 ...
show more
185.113.140.131 - - [12/Sep/2026:09:36:26 +0000] "GET /.env HTTP/1.1" 404 6852 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:26:26
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:26:22.107054 2026] [security2:error] [pid 20023:tid 20023] [client 185.113.140.131:55466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.120"] [uri "/.env"] [unique_id "aqUavqiTQUhUtPD2UCrKLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rip
2026-09-12 09:09:45
(12 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:08:18
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:08:14.362516 2026] [security2:error] [pid 24698:tid 24698] [client 185.113.140.131:60072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.101"] [uri "/.env"] [unique_id "aqUWfp6CaYu5EyAxSqz5TQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:49:56
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:49:49.351767 2026] [security2:error] [pid 14065:tid 14065] [client 185.113.140.131:51173] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.95"] [uri "/.env"] [unique_id "aqUSLT3HQqBOUf69WNwK6QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:30:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.113.140.131 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:30:19.768326 2026] [security2:error] [pid 19434:tid 19434] [client 185.113.140.131:61273] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.200"] [uri "/.env"] [unique_id "aqUNm_6YA6i3KlYs2AbffAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2026-09-12 08:25:08
(13 hours ago)
Blocked by UFW (TCP on 80)
Source port: 55781
TTL: 111
Packet length: 52
TOS: 0x0A
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 55781
TTL: 111
Packet length: 52
TOS: 0x0A
This report (for 185.113.140.131) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack