๐บ๐ธ
TPI-Abuse
2026-06-18 19:41:02
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 15:40:53.427258 2026] [security2:error] [pid 4877:tid 4877] [client 202.74.74.86:54350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hydrogenplus.net"] [uri "/.env"] [unique_id "ajRJxVUEjtEFwZ9ku1ZRkAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-16 21:59:21
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-15.
show less
Web App Attack
SSH
Hacking
๐ง๐ช
voormedia
2026-06-16 04:35:44
(3 days ago)
Accessed trap at '/.env'
Web App Attack
Anonymous
2026-06-16 02:52:53
(3 days ago)
apache-auth
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 00:57:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 20:57:11.974996 2026] [security2:error] [pid 9748:tid 9748] [client 202.74.74.86:55794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.matchob.utilis.net"] [uri "/.env"] [unique_id "ajCfZ9nQkSB-anlOmMiumgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sdos.es
2026-06-14 23:33:12
(4 days ago)
"Restricted File Access Attempt - Matched Data: /.env found within REQUEST_FILENAME: /.env"
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-14 23:05:28
(4 days ago)
Try to access /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:52:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:52:49.362547 2026] [security2:error] [pid 32436:tid 32436] [client 202.74.74.86:40756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.melton.space"] [uri "/.env"] [unique_id "ai8isVpkBxCI3ygL46JVDwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:18:01
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:17:53.580751 2026] [security2:error] [pid 412:tid 412] [client 202.74.74.86:60296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "osmanbozkurt.pist.org.tr"] [uri "/.env"] [unique_id "ai7GIcnsUrFahs2ttA45GgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-06-14 15:11:39
(4 days ago)
Accessed trap at '/.env'
Web App Attack
๐ฉ๐ช
check-the-sum.fr
2026-06-14 13:31:03
(4 days ago)
Port Scanning
Port Scan
๐ณ๐ด
jad-abuse
2026-06-14 12:36:53
(4 days ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. O ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:50:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:50:29.907073 2026] [security2:error] [pid 15948:tid 15948] [client 202.74.74.86:35788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.andrewweigel.name"] [uri "/.env"] [unique_id "ai4I5b1nTxx0NKE2x1kd6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-06-14 00:54:37
(5 days ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 00:36:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io) ...
show more
(mod_security) mod_security (id:210492) triggered by 202.74.74.86 (ip-86-74-74-202.wjv-1.biznetg.io): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 20:36:37.841972 2026] [security2:error] [pid 20830:tid 20849] [client 202.74.74.86:34388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.icert.io"] [uri "/.env"] [unique_id "ai33lUPpkrCcmQ25gYR_3gAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack