🇺🇸
TPI-Abuse
2026-09-09 17:16:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:15:56.741207 2026] [security2:error] [pid 6735:tid 6735] [client 196.119.118.1:58013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boyt.org"] [uri "/.env"] [unique_id "aqGUTCGdULR7QwAdkfhQ8QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:49:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:49:07.987921 2026] [security2:error] [pid 5304:tid 5304] [client 196.119.118.1:60372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackriverarc.org"] [uri "/.env"] [unique_id "aqGOA52pBwQS1UX2BQGx1wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:25:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:25:44.681181 2026] [security2:error] [pid 23921:tid 23921] [client 196.119.118.1:58002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americancryonics.org"] [uri "/.env"] [unique_id "aqF6eHitj_LvMoylo4lWNAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
spot
2026-09-09 15:21:51
(3 hours ago)
196.119.118.1 - - [09/Sep/2026:16:21:50 +0100] "GET /.env HTTP/1.1" 301 604 "-" "Mozilla/5.0 (Macint ...
show more
196.119.118.1 - - [09/Sep/2026:16:21:50 +0100] "GET /.env HTTP/1.1" 301 604 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack
VPN IP
🇺🇸
TPI-Abuse
2026-09-09 15:08:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:08:39.049303 2026] [security2:error] [pid 31931:tid 31931] [client 196.119.118.1:59809] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accordionclub.org"] [uri "/.env"] [unique_id "aqF2d1HCBZfvptQOqkhKrgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 14:40:03
(4 hours ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:26:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:26:40.441601 2026] [security2:error] [pid 9037:tid 9037] [client 196.119.118.1:56035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buggyshop.org"] [uri "/.env"] [unique_id "aqFsoM1gU-LFcPJI4uIbEQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:05:48
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:05:45.466910 2026] [security2:error] [pid 1412694:tid 1412778] [client 196.119.118.1:59416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviscountyossr.org"] [uri "/.env"] [unique_id "aqFnuY-lYoRUXM-16xoIywAAAhM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:44:02
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:43:57.444826 2026] [security2:error] [pid 5062:tid 5062] [client 196.119.118.1:63739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtempleofdeliverance.org"] [uri "/.env"] [unique_id "aqFinYmhai1QCNsxl5bQTAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:17:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:17:13.666501 2026] [security2:error] [pid 1914:tid 1914] [client 196.119.118.1:57195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackberrycircle.org"] [uri "/.env"] [unique_id "aqFcWe92-BldRQCS3PDH0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bescared
2026-09-09 13:00:45
(6 hours ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:59:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:59:17.229406 2026] [security2:error] [pid 1874:tid 1874] [client 196.119.118.1:52967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "budinger.org"] [uri "/.env"] [unique_id "aqFYJe7KvmWibiCtr89QNQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-09-09 12:43:40
(6 hours ago)
Scanning for exploits - /.env
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:41:44
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 196.119.118.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:41:40.956344 2026] [security2:error] [pid 6982:tid 6982] [client 196.119.118.1:58169] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "chuckwagon.org"] [uri "/.env"] [unique_id "aqFUBNMPuq7DWE-BX2db6wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Dominik Lysiak
2026-09-09 12:29:25
(6 hours ago)
196.119.118.1 - - [09/Sep/2026:14:29:24 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macint ...
show more
196.119.118.1 - - [09/Sep/2026:14:29:24 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
196.119.118.1 - - [09/Sep/2026:14:29:24 +0200] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
196.119.118.1 - - [09/Sep/2026:14:29:24 +0200] "GET /.env HTTP/1.1" 200 9893 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
Web App Attack