๐บ๐ธ
TPI-Abuse
2026-09-23 18:26:42
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:26:36.299575 2026] [security2:error] [pid 7787:tid 7787] [client 185.215.246.92:52619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.23"] [uri "/.env"] [unique_id "arQZ3BfckiHeepF6Z3xEOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:27:56
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:27:48.785199 2026] [security2:error] [pid 30407:tid 30407] [client 185.215.246.92:61848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.234"] [uri "/.env"] [unique_id "arQMFA1WO4wsVGX1AE7QwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-09-23 15:58:57
(13 hours ago)
[AUTORAVALT][[23/09/2026 - 12:58:57 -03:00 UTC]
Attack from [185.215.246.92] Action: BLocKed
Hackin ...
show more
[AUTORAVALT][[23/09/2026 - 12:58:57 -03:00 UTC]
Attack from [185.215.246.92] Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/solutions.
]
...
show less
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-23 15:50:30
(14 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-4)
Hacking
Bad Web Bot
๐บ๐ธ
jcbriar
2026-09-23 15:36:55
(14 hours ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ฉ๐ช
Tamsy
2026-09-23 15:25:01
(14 hours ago)
HTTPD - 4xx scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:38:53
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:38:48.966684 2026] [security2:error] [pid 29184:tid 29184] [client 185.215.246.92:55633] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.30"] [uri "/.env"] [unique_id "arPWaCx3WGJbGg5FzmLO1AAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
service Informatique
2026-09-23 04:00:37
(1 day ago)
GET /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:33:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:33:45.667640 2026] [security2:error] [pid 12990:tid 12990] [client 185.215.246.92:55068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.16"] [uri "/.env"] [unique_id "arJnmUSK7VJIM29lviJcvQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:10:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:10:06.595267 2026] [security2:error] [pid 28100:tid 28100] [client 185.215.246.92:64759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.211"] [uri "/.env"] [unique_id "arJiDpBDOnBWpdP6Sic3jgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:46:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:46:16.566922 2026] [security2:error] [pid 29522:tid 29522] [client 185.215.246.92:64271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.195"] [uri "/.env"] [unique_id "arJceJVO8DhqDhsZTTYjoQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-22 10:10:03
(1 day ago)
Repeated exploit attempts, for example: / 0x%5B%5D=androxgh0st (HTTP/1.1 port 443)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:08:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 185.215.246.92 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:08:36.521865 2026] [security2:error] [pid 29381:tid 29381] [client 185.215.246.92:53145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.176"] [uri "/.env"] [unique_id "arJTpIsYxVbQvFeNOO5MowAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-22 09:35:06
(1 day ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-22 09:34:35.117 |
Web App Attack
๐ฉ๐ช
tsZero
2026-09-22 09:25:47
(1 day ago)
Scan example: path=/.env status=404
Hacking