🇺🇸
TPI-Abuse
2026-09-09 15:48:22
(14 minutes ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:48:17.487043 2026] [security2:error] [pid 21172:tid 21172] [client 198.135.53.12:35790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "areafinancieratf.com"] [uri "/.env"] [unique_id "aqF_wZzbU97XyG4f4u4lEQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ut-addicted.com
2026-09-09 13:55:15
(2 hours ago)
\[Wed Sep 09 15:55:14.127816 2026\] \[:error\] \[pid 28148:tid 140352398731008\] \[client 198.135.53 ...
show more
\[Wed Sep 09 15:55:14.127816 2026\] \[:error\] \[pid 28148:tid 140352398731008\] \[client 198.135.53.12:37692\] \[client 198.135.53.12\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "crx.it"\] \[uri "/.env"\] \[unique_id "aqFlQuSiy0TMtlW7h8g-UwAAANY"\]
show less
Brute-Force
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-09 12:20:34
(3 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
Lee Daniel
2026-09-09 12:04:49
(3 hours ago)
198.135.53.12 - - [09/Sep/2026:08:04:48 -0400] "GET /.env HTTP/1.1" 403 6327 "-" "Mozilla/5.0 (X11; ...
show more
198.135.53.12 - - [09/Sep/2026:08:04:48 -0400] "GET /.env HTTP/1.1" 403 6327 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:55:44
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:55:37.341635 2026] [security2:error] [pid 21924:tid 21924] [client 198.135.53.12:54758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pointillistic.com"] [uri "/.env"] [unique_id "aqFJOY138eO24u0z7Zx9IgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-09 11:48:11
(4 hours ago)
Scan of vulnerable files
Web App Attack
🇸🇪
Per-Erik Runebert
2026-09-09 08:40:40
(7 hours ago)
Malicious vulnerability hacking attacks
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:48:29
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:48:22.779014 2026] [security2:error] [pid 31708:tid 31708] [client 198.135.53.12:38596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "penninesolutions.com"] [uri "/.env"] [unique_id "aqDXBhbcUhDuunhM39Fw-wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-09-09 03:32:31
(12 hours ago)
Scanning for exploits - /.env
Web App Attack
🇩🇪
sdos.es
2026-09-09 03:19:03
(12 hours ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:49:39
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:49:34.174886 2026] [security2:error] [pid 32527:tid 32527] [client 198.135.53.12:54400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "normteslaa.com"] [uri "/.env"] [unique_id "aqDJPtDd81O59y3yTiHwVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 02:08:28
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-09 02:08 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:06:33
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:06:29.039884 2026] [security2:error] [pid 13940:tid 13940] [client 198.135.53.12:46378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wurkroom.biz"] [uri "/.env"] [unique_id "aqC_JaMgWa30laRd_EtbhAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:07:53
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:07:45.457517 2026] [security2:error] [pid 24327:tid 24327] [client 198.135.53.12:49466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "britishfolk.org"] [uri "/.env"] [unique_id "aqCxYXzH6SAYU-osJtVHkwAAAGM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:32:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.135.53.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:32:06.545841 2026] [security2:error] [pid 21093:tid 21093] [client 198.135.53.12:37518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.post-therapyreconditioning.com"] [uri "/.env"] [unique_id "aqCa9iQwKsAewUD5JIpfKAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack