๐บ๐ธ
NXTwoThou
2026-06-02 06:41:39
(1 day ago)
/api/.env
Web App Attack
๐ซ๐ท
masterguru
2026-06-02 06:19:33
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 05:59:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:59:01.302643 2026] [security2:error] [pid 28980:tid 29072] [client 185.166.38.86:17156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hnssales.com"] [uri "/app/.env"] [unique_id "ah5xJT6GOpaoaFxrxrLdqgAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 04:54:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:54:03.959571 2026] [security2:error] [pid 29915:tid 29915] [client 185.166.38.86:39152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "runnercomics.com"] [uri "/dev/.env"] [unique_id "ah5h61cQSMWZmXcwYWbKEQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 04:19:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:19:07.139691 2026] [security2:error] [pid 1637:tid 1637] [client 185.166.38.86:45568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canfieldnyc.com"] [uri "/.env"] [unique_id "ah5Zu6c8oVP5KEZht8_2GQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-02 04:11:19
(1 day ago)
Web vulnerability probing: /api/.env
Web App Attack
๐ฉ๐ช
raph
2026-06-02 03:17:28
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-02 03:13:06
(1 day ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 02:58:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 22:58:47.383171 2026] [security2:error] [pid 26028:tid 26028] [client 185.166.38.86:29474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gasoilliquidsdaily.com"] [uri "/admin/.env"] [unique_id "ah5G57v8PQvl-fvUZhiepgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-06-02 02:57:03
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 185.166.38.86 (FR/France/-): 5 in the last 3600 ...
show more
(mod_security) mod_security (id:949110) triggered by 185.166.38.86 (FR/France/-): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 02:43:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 22:43:10.284413 2026] [security2:error] [pid 19109:tid 19109] [client 185.166.38.86:22660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bostonscience.com"] [uri "/dev/.env"] [unique_id "ah5DPkIi_C_dC2SXE3mk6gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 02:09:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 22:09:08.744576 2026] [security2:error] [pid 12714:tid 12714] [client 185.166.38.86:38492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "automatebi.com"] [uri "/backend/.env"] [unique_id "ah47RIJV4Ao7G0Wv5qRRUgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 00:45:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 20:45:29.533659 2026] [security2:error] [pid 16936:tid 16936] [client 185.166.38.86:60302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itsupitsdown.com"] [uri "/dev/.env"] [unique_id "ah4nqYbOicAFgLhbbVS1gQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 23:45:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 19:45:15.459578 2026] [security2:error] [pid 23406:tid 23406] [client 185.166.38.86:44966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sfgardening.com"] [uri "/core/.env"] [unique_id "ah4ZiwwLxOpah0Py_wXsFwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 23:10:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.166.38.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 19:10:23.288220 2026] [security2:error] [pid 30223:tid 30223] [client 185.166.38.86:18798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darlinghernandez.com"] [uri "/api/.env"] [unique_id "ah4RXyL4lOdvqOWBozfMeQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack