๐ช๐ธ
Gem
2026-06-19 22:13:11
(3 days ago)
Unauthorized web scan.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:46:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:46:49.797205 2026] [security2:error] [pid 1844:tid 1844] [client 202.162.35.3:51760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.tand.es"] [uri "/.env"] [unique_id "ai9LeTXf6Q97y7nX3ha0TAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:18:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:18:00.960089 2026] [security2:error] [pid 24319:tid 24319] [client 202.162.35.3:52266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.equipoperu.org"] [uri "/.env"] [unique_id "ai9EuEda__wHHo9PVWadxgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:37:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:37:42.498187 2026] [security2:error] [pid 11337:tid 11337] [client 202.162.35.3:54606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.empoweruamerica.empoweruohio.org"] [uri "/.env"] [unique_id "ai87RnP1zDJ4P7oWpWdZfgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 13:22:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 09:22:47.375465 2026] [security2:error] [pid 29656:tid 29656] [client 202.162.35.3:36716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iwsa.info"] [uri "/.env"] [unique_id "ai6rJ80FPI5cQ0ePCBnTuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 13:05:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 09:05:11.266523 2026] [security2:error] [pid 29144:tid 29144] [client 202.162.35.3:49964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infodrop.info"] [uri "/.env"] [unique_id "ai6nB-nBao1L9_4IYB3mngAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 12:32:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 08:32:08.698192 2026] [security2:error] [pid 22656:tid 22656] [client 202.162.35.3:56500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hiddenhistory.info"] [uri "/.env"] [unique_id "ai6fSHZ6aF-bMWUV4i92mgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 08:47:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 04:47:18.477724 2026] [security2:error] [pid 17099:tid 17099] [client 202.162.35.3:40776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mylert.sguard.co"] [uri "/.env"] [unique_id "ai5qlr1UsJGlQu9wydw3_AAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Guardian
2026-06-14 03:23:13
(1 week ago)
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x2), Unauthorized attempt to retr ...
show more
Multi abuses [2]: Unauthorized connection attempt / Port scanning (x2), Unauthorized attempt to retrieve configuration file
202.162.35.3 [14/Jun/2026:03:23:12] "GET / HTTP/1.1"
202.162.35.3 [14/Jun/2026:03:23:12] "GET /users/sign_in HTTP/1.1"
202.162.35.3 [14/Jun/2026:03:23:13] "GET /.env HTTP/1.1"
show less
Port Scan
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-13 07:20:48
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-06-13 07:02:05
(1 week ago)
Scanning for exploits - /.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-12 22:55:01
(1 week ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 14:28:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 10:28:22.965600 2026] [security2:error] [pid 11120:tid 11120] [client 202.162.35.3:54290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sydat.se"] [uri "/.env"] [unique_id "aiwXhkihpSxy3qIYrhFhoAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 14:08:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 10:08:23.828753 2026] [security2:error] [pid 21758:tid 21758] [client 202.162.35.3:52266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.malarbodentrollhattan.se"] [uri "/.env"] [unique_id "aiwS1xyoDAEhyw-Dr9AQcQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 04:50:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.n ...
show more
(mod_security) mod_security (id:210492) triggered by 202.162.35.3 (202.162.35.3-static.reverse.uii.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:50:12.606578 2026] [security2:error] [pid 16073:tid 16073] [client 202.162.35.3:42240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cas.majesticsolutions.co"] [uri "/.env"] [unique_id "aiuQBLeiBOOsOXr5U4cmSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack