๐บ๐ธ
TPI-Abuse
2026-09-17 15:55:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:55:12.061331 2026] [security2:error] [pid 28722:tid 28722] [client 213.219.180.113:49779] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bendersite.com"] [uri "/.env"] [unique_id "aqwNYFP3iGVQzrjeifG99wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-17 15:27:47
(3 hours ago)
213.219.180.113 - - [17/Sep/2026:11:27:46 -0400] "GET /.env HTTP/1.1" 403 6380 "-" "Mozilla/5.0 (X11 ...
show more
213.219.180.113 - - [17/Sep/2026:11:27:46 -0400] "GET /.env HTTP/1.1" 403 6380 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-17 15:05:16
(3 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 15:03:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 11:03:17.936712 2026] [security2:error] [pid 3185:tid 3185] [client 213.219.180.113:43876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avrknives.com"] [uri "/.env"] [unique_id "aqwBNXlK06B4ESfS3l2omwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 14:34:56
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:34:52.109737 2026] [security2:error] [pid 31705:tid 31705] [client 213.219.180.113:38214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asociacionmutualsanjose.com"] [uri "/.env"] [unique_id "aqv6jJ4XM7RM5LemuWGxUwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-09-17 14:29:44
(4 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1. No raw log data included.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 14:06:17
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:06:13.730860 2026] [security2:error] [pid 16216:tid 16216] [client 213.219.180.113:56054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "applemaccomputerconsulting.com"] [uri "/.env"] [unique_id "aqvz1Qq1z-Bfbrh94Ky9fAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-17 13:47:44
(4 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 13:43:10
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:43:07.013190 2026] [security2:error] [pid 802:tid 802] [client 213.219.180.113:62967] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amsterdamlayovers.com"] [uri "/.env"] [unique_id "aqvua_LuE2vJGElbo6O-8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 13:24:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:24:34.123324 2026] [security2:error] [pid 7255:tid 7255] [client 213.219.180.113:59101] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allmyartprojects.com"] [uri "/.env"] [unique_id "aqvqEgVq7BegKaHF-QccWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-17 13:22:35
(5 hours ago)
[ThuSep1715:22:31.2443702026][security2:error][pid260185:tid260278][client213.219.180.113:0]ModSecur ...
show more
[ThuSep1715:22:31.2443702026][security2:error][pid260185:tid260278][client213.219.180.113:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"allegrafamiglia.ch\"][uri\"/.env\"][unique_id\"aqvpl9C2Jufdnx9AR1lYoQAAAVQ\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 13:21:00
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-17 13:21 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-17 13:15:36
(5 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.alchemy.com.gr; logs=/var/log/httpd/domains/alchemy.com. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.alchemy.com.gr; logs=/var/log/httpd/domains/alchemy.com.gr.log; samples=/.env
show less
Hacking
Web App Attack
Anonymous
2026-09-17 13:00:04
(5 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:52:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 213.219.180.113 (email.btr-services.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:52:09.708902 2026] [security2:error] [pid 7145:tid 7145] [client 213.219.180.113:51128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agenticapocalypse.com"] [uri "/.env"] [unique_id "aqviefyabd4E3tKMWCFZZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack