๐ฌ๐ง
[email protected]
2025-12-11 00:54:00
(7 months ago)
...
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2025-12-10 22:59:02
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-12-09.
show less
Hacking
Web App Attack
SSH
๐ณ๐ฑ
jjnxpct
2025-12-10 04:49:15
(7 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .env found within REQUEST_FILENAME: /.env]
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2025-12-10 02:06:21
(7 months ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-12-09 22:59:29
(7 months ago)
Auto-ban: >3000 req/min op 2025-12-09
Hacking
Web App Attack
SSH
๐ฉ๐ช
Hydra-Shield.fr
2025-12-09 18:20:16
(7 months ago)
Directory Traversal on: /.env
Web App Attack
๐ง๐พ
lns.bz
2025-12-09 17:45:03
(7 months ago)
.env scanning [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 14:18:57
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 09:18:52.817777 2025] [security2:error] [pid 24833:tid 24864] [client 196.75.159.200:64853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bertdecoutere.name"] [uri "/.env"] [unique_id "aTgvzKttdr3go2F-sy_6SAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2025-12-09 12:49:21
(7 months ago)
Web app attack
Exploited Host
Web App Attack
๐ง๐ช
madeit
2025-12-09 12:43:41
(7 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 09:36:53
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 04:36:46.303174 2025] [security2:error] [pid 22051:tid 22051] [client 196.75.159.200:55434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atsgroup.llc"] [uri "/.env"] [unique_id "aTftrhmRS8w_I4O5QuHUmQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 09:11:59
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 04:11:54.100893 2025] [security2:error] [pid 16893:tid 16893] [client 196.75.159.200:57207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "a1laha.com"] [uri "/.env"] [unique_id "aTfn2hzE0P_1wNravvQLOwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 08:35:19
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 196.75.159.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 03:35:14.391710 2025] [security2:error] [pid 13325:tid 13325] [client 196.75.159.200:50528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1800glass.com"] [uri "/.env"] [unique_id "aTffQi5gdkByBH5XKijzgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2025-12-09 07:21:19
(7 months ago)
Scanning for exploits - /.env
Web App Attack
Anonymous
2025-12-09 07:05:07
(7 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host