๐บ๐ธ
TPI-Abuse
2026-06-22 03:38:41
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 23:38:38.313952 2026] [security2:error] [pid 22898:tid 22898] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:64372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cathybermanmft.com"] [uri "/.env/.env.bak"] [unique_id "ajiuPhtH0RPl8T9-3o0mfQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 03:07:03
(6 days ago)
Automated web scanner. Requested suspicious paths: /phpinfo.php. UTC: 2026-06-22 03:04:42.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 02:36:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 22:36:39.665848 2026] [security2:error] [pid 20307:tid 20307] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:50480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brigittecavanagh.com"] [uri "/.env/.env.bak"] [unique_id "ajift8aYEytwBNuD83P14QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-21 23:55:08
(6 days ago)
[MonJun2201:55:03.2090222026][security2:error][pid1362735:tid1362750][client2001:448a:a071:df9:f555: ...
show more
[MonJun2201:55:03.2090222026][security2:error][pid1362735:tid1362750][client2001:448a:a071:df9:f555:f43c:fcc2:7a2b:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"casacarmen.ch\"][uri\"/.env/.env.bak\"][unique_id\"ajh515X6WTT87FScGC7rYAAAAMw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 22:51:19
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 18:51:11.362703 2026] [security2:error] [pid 19088:tid 19088] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:56354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carolmaalouf.com"] [uri "/.env/.env.bak"] [unique_id "ajhq3-a5YfYxPfXlntQ9MwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
SOC [GOLINE SA]
2026-06-21 22:42:09
(6 days ago)
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Se ...
show more
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Severity: 1-2 | Category: Security Threat === SOURCE === IP: 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (IPv6) | Port: N/A | Country: Indonesia | ISP: TELKOMNET-20050901 | rDNS: None === TARGET === Host: lg.goline.ch | IP: lg.goline.ch | Port: multiple | Protocol: TCP/UDP | App: N/A === RESPONSE === Time: 2026-06-22 00:42:09 | Action: Blocked
show less
Port Scan
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-21 22:18:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 18:18:42.359918 2026] [security2:error] [pid 23579:tid 23579] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:60132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carlgrauelcsw.com.onyxcc.com"] [uri "/.env/.env.bak"] [unique_id "ajhjQhOguE_7ALK2jZLc2wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-21 22:00:15
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-20.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-21 17:18:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 13:18:13.480863 2026] [security2:error] [pid 21315:tid 21315] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:62365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookofraphael.com"] [uri "/.env/.env.bak"] [unique_id "ajgc1RjIgrcq-SZGOYg-eQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
0x44
2026-06-21 08:21:01
(1 week ago)
Abusive host detected - Web probing for vulnerabilities
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-21 07:50:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 03:50:50.352158 2026] [security2:error] [pid 9667:tid 9667] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:54343] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balirealestateadvertiser.com"] [uri "/.env/.env.bak"] [unique_id "ajeX2mp3i8CQttgryU9SMAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-21 07:30:34
(1 week ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env/.env.bak
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-06-21 05:13:32
(1 week ago)
5 attacks on PHP URLs, env grabbing URLs, password grabbing URLs:
GET /index.php HTTP/1.1
GET /.env/ ...
show more
5 attacks on PHP URLs, env grabbing URLs, password grabbing URLs:
GET /index.php HTTP/1.1
GET /.env/.env.bak HTTP/1.1
GET /.aws/credentials HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-21 04:09:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:448a:a071:df9:f555:f43c:fcc2:7a2b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:09:37.323911 2026] [security2:error] [pid 30962:tid 30962] [client 2001:448a:a071:df9:f555:f43c:fcc2:7a2b:57053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackjobsnetwork.com"] [uri "/.env/.env.bak"] [unique_id "ajdkASr-OMxEe5tW-JTmeQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 00:05:06
(1 week ago)
PHP file probing detected by Fail2Ban
Web App Attack