๐ซ๐ท
LRNP
2026-09-20 07:38:20
(2 hours ago)
_:80 20.110.231.139 - - [20/Sep/2026:07:38:19 +0000] "GET /.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 ( ...
show more
_:80 20.110.231.139 - - [20/Sep/2026:07:38:19 +0000] "GET /.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 06:55:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 02:55:39.877899 2026] [security2:error] [pid 27985:tid 27985] [client 20.110.231.139:58861] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lesdaniels.com"] [uri "/.env"] [unique_id "aq-Dax3BVC1MsKhMTR8yRwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 06:49:57
(2 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-20 04:44:29
(5 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 04:32:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 00:32:29.089939 2026] [security2:error] [pid 19876:tid 19876] [client 20.110.231.139:58786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leolion.net"] [uri "/.env"] [unique_id "aq9h3ZkON1U1oMQ4XzJZtQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 03:54:51
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 23:54:44.083637 2026] [security2:error] [pid 7205:tid 7205] [client 20.110.231.139:60234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lenorasflowers.com"] [uri "/.env"] [unique_id "aq9ZBJPDpHRwN4dMPifLKgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-20 02:31:53
(7 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 1. First blocked: 2026-09-20.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-20 02:30:06
(7 hours ago)
Domain : lembas.co.uk
Rule : env
2026-09-20 02:28:07 ***hidden-privacy*** GET /.env - 443 - 20.110.2 ...
show more
Domain : lembas.co.uk
Rule : env
2026-09-20 02:28:07 ***hidden-privacy*** GET /.env - 443 - 20.110.231.139 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 - lembas.co.uk 404 0 2 1416 167 85 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-20 01:51:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:51:29.351536 2026] [security2:error] [pid 29434:tid 29434] [client 20.110.231.139:51187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lekacos.com"] [uri "/.env"] [unique_id "aq88IS9IIWdRczjvEV002wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 01:17:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 21:17:37.158872 2026] [security2:error] [pid 28333:tid 28333] [client 20.110.231.139:49969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leighcunningham.com"] [uri "/.env"] [unique_id "aq80MYbmL9VN_ocl47zWaAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 01:13:02
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐ฌ๐ง
andypiper
2026-09-20 01:01:39
(8 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ง๐ท
Halux
2026-09-20 00:52:48
(8 hours ago)
20.110.231.139 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 00:13:53
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.110.231.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 20:13:48.812220 2026] [security2:error] [pid 30222:tid 30222] [client 20.110.231.139:59513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "legendesignhouse.com"] [uri "/.env"] [unique_id "aq8lPGFEUOmf-HGeVQxALwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-19 23:58:03
(9 hours ago)
20.110.231.139 - - [20/Sep/2026:01:58:02 +0200] "GET /.env HTTP/1.1" 302 397 "-" "Mozilla/5.0 (Windo ...
show more
20.110.231.139 - - [20/Sep/2026:01:58:02 +0200] "GET /.env HTTP/1.1" 302 397 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack