๐จ๐ญ
zynex
2026-09-03 23:47:18
(42 minutes ago)
URL Probing: /@fs/app/.env
Web App Attack
๐ง๐ช
cmbplf
2026-09-03 23:05:20
(1 hour ago)
12.791 requests from abuseipdb.com blacklisted IP (7mos3w20h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-03 22:55:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:55:22.486421 2026] [security2:error] [pid 20203:tid 20203] [client 207.175.15.249:50338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dymesich.com"] [uri "/@fs/.env"] [unique_id "apn62nIy3n3sbCUhK_lSgQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:28:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:28:04.017455 2026] [security2:error] [pid 12216:tid 12236] [client 207.175.15.249:55764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.frasers.biz"] [uri "/@fs/..%252f..%252f..%252f..%252f..%252froot/.env"] [unique_id "apn0dN_vPehdh5JNn5rPbgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 22:19:21
(2 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-03 22:16:12
(2 hours ago)
Bot / seems abusive / Apache connections: 77
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:09:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:09:08.740494 2026] [security2:error] [pid 20823:tid 20823] [client 207.175.15.249:64968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.robcruickshank.net"] [uri "/@fs/src/.env"] [unique_id "apnwBM7B6zZkCHTqpnfh4gAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-03 21:59:22
(2 hours ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
๐บ๐ธ
WellSpring
2026-09-03 21:44:17
(2 hours ago)
env leak on 530.today/@fs/home/ubuntu/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ง๐ช
taivas.nl
2026-09-03 21:02:11
(3 hours ago)
Bad_requests
Bad Web Bot
Anonymous
2026-09-03 20:54:17
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 207.175.15.249 (BE/Belgium/249.15.175.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 207.175.15.249 (BE/Belgium/249.15.175.207.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-03 20:45:25
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:45:19.701856 2026] [security2:error] [pid 11405:tid 11425] [client 207.175.15.249:50902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rmoeis.com"] [uri "/@fs/root/.env"] [unique_id "apncX_4vOTAZSDYUl_y9qQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-03 20:08:52
(4 hours ago)
tcp port scan (216 or more attempts)
Port Scan
๐ซ๐ท
stefaniak41500
2026-09-03 20:07:37
(4 hours ago)
Shield Guard: AbuseIPDB: 92% (trรจs malveillant) | Honeypot: /id_rsa
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:04:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.15.249 (249.15.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:04:07.145611 2026] [security2:error] [pid 20244:tid 20258] [client 207.175.15.249:44702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.tierrasolymar.com"] [uri "/@fs/.env"] [unique_id "apnSt3HVWAc0aHRu_f38RwAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack