๐บ๐ธ
TPI-Abuse
2026-01-06 07:32:23
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzul ...
show more
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 02:32:15.875797 2026] [security2:error] [pid 32655:tid 32655] [client 198.44.131.162:57161] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kwtlaw.com"] [uri "/.env"] [unique_id "aVy6f9va5yZ5I7S-oSi8cQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-06 07:06:57
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzul ...
show more
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 02:06:49.813248 2026] [security2:error] [pid 14724:tid 14724] [client 198.44.131.162:54167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "silvermoonherbals.com"] [uri "/.env"] [unique_id "aVy0iZ1QELd3zx1pATIA6gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-01-06 06:50:09
(8 months ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-06 05:17:40
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzul ...
show more
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 06 00:17:37.920804 2026] [security2:error] [pid 9117:tid 9117] [client 198.44.131.162:58361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jesuspuzzle.com"] [uri "/.env"] [unique_id "aVya8aHl0CUbGLXScMt4PAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
VXG-NET
2026-01-06 04:02:25
(8 months ago)
port=80, indicator_type=info-leak
Hacking
๐บ๐ธ
TPI-Abuse
2026-01-06 03:33:06
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzul ...
show more
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 22:33:00.944723 2026] [security2:error] [pid 978666:tid 978728] [client 198.44.131.162:24221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "managementconsultant.us"] [uri "/.env"] [unique_id "aVyCbHN2I2PNH-rr_Y45fQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-01-06 03:01:57
(8 months ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: python-reques ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: foro.elhacker.net userAgent: python-requests/2.32.3 Action: block Source: firewallManaged ASN Description: TZULO Country: US Method: GET Timestamp: 2026-01-06T03:01:57Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-06 02:46:52
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzul ...
show more
(mod_security) mod_security (id:210492) triggered by 198.44.131.162 (static-198-44-131-162.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 05 21:46:48.624247 2026] [security2:error] [pid 23001:tid 23001] [client 198.44.131.162:51367] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theateroobleck.com"] [uri "/.env"] [unique_id "aVx3mEfNoOcU_ewQrMrM2QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-01-06 02:18:18
(8 months ago)
IM360 WAF: Laravel .env file access
Web App Attack
Anonymous
2025-04-09 11:18:48
(1 year ago)
Web Server atack
...
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-01-21 10:06:22
(1 year ago)
DDoS Attack