Anonymous
2026-06-13 20:44:55
(1 minute ago)
213.173.111.73 - - [13/Jun/2026:22:44:55 +0200] "GET /.env HTTP/1.1" 404 6840 "-" "Mozilla/5.0 (Wind ...
show more
213.173.111.73 - - [13/Jun/2026:22:44:55 +0200] "GET /.env HTTP/1.1" 404 6840 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 20:40:09
(5 minutes ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 16:40:04.167249 2026] [security2:error] [pid 26170:tid 26186] [client 213.173.111.73:43442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cynosureservices.cynosureinternetservices.com"] [uri "/.env"] [unique_id "ai3AJEjLZh8-DShFbIxGnQAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-13 20:35:20
(10 minutes ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ง๐ช
cmbplf
2026-06-13 20:11:49
(34 minutes ago)
12.483 requests from abuseipdb.com blacklisted IP (1yr4mos1d)
Brute-Force
Bad Web Bot
๐ซ๐ฎ
payincog
2026-06-13 20:06:10
(39 minutes ago)
Date: Jun 13 22:31:28 2026 EAT | Reported IP: 213.173.111.73 mod_security | id: 930130 949110 920440 ...
show more
Date: Jun 13 22:31:28 2026 EAT | Reported IP: 213.173.111.73 mod_security | id: 930130 949110 920440 | RO/pay.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 5); Inbound Anomaly Score Exceeded (Total Score: 5); Inbound Anomaly Score Exceeded (Total Score: 5); URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Re
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 19:45:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:45:38.709082 2026] [security2:error] [pid 2066:tid 2066] [client 213.173.111.73:41068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.basse.lahamradio.com"] [uri "/.env"] [unique_id "ai2zYkvucSVOTV9MpoGfeQAAAGs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-06-13 19:28:38
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 19:28:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:28:03.399249 2026] [security2:error] [pid 19786:tid 19786] [client 213.173.111.73:47578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web179.dnchosting.com"] [uri "/.env"] [unique_id "ai2vQy70FPLxvrrVo4wyqgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 18:52:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 14:52:47.717167 2026] [security2:error] [pid 11439:tid 11439] [client 213.173.111.73:37774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.csiwebdesigns.com.fiyaplatform.com"] [uri "/.env"] [unique_id "ai2m_9jtf1uNmqXnM09uPgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-13 18:00:04
(2 hours ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
MBombeck
2026-06-13 17:58:48
(2 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 17:42:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:42:46.532357 2026] [security2:error] [pid 31505:tid 31505] [client 213.173.111.73:36664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.substack.diegolaje.com"] [uri "/.env"] [unique_id "ai2WllokTGtc0MlcWYL59AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stylottica
2026-06-13 17:29:01
(3 hours ago)
PrestaShop Security Module: Suspicious path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 17:18:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 213.173.111.73 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:18:27.082986 2026] [security2:error] [pid 10229:tid 10229] [client 213.173.111.73:54604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.firingsquadfilms.com.interforce.com"] [uri "/.env"] [unique_id "ai2Q494IBx9GYDmzJNyH7gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-13 16:48:52
(3 hours ago)
Web vulnerability probing: /.env.staging
Web App Attack