๐บ๐ธ
TPI-Abuse
2026-09-20 08:24:22
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 04:24:13.731594 2026] [security2:error] [pid 29254:tid 29254] [client 213.254.175.235:52849] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "192.64.150.240"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "aq-YLZG55VBgoHanYVKEYAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
PhilGoode
2026-09-20 04:22:39
(3 weeks ago)
HTTP web-application probing on TCP 80 requested a host-specific .env path. Observed by a web honeyp ...
show more
HTTP web-application probing on TCP 80 requested a host-specific .env path. Observed by a web honeypot.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:44:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:44:43.943783 2026] [security2:error] [pid 32273:tid 32273] [client 213.254.175.235:38517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.57"] [uri "/conf/.env"] [unique_id "aq7mK5cYC0LE_sVgi07G5AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
msavo
2026-09-19 14:04:01
(3 weeks ago)
CIR Sentinel: env_probe_permanent; 1 requests in 60s; targets=/wp-content/.env; permanently blocked ...
show more
CIR Sentinel: env_probe_permanent; 1 requests in 60s; targets=/wp-content/.env; permanently blocked by the firewall.
show less
Web App Attack
๐ซ๐ท
id2i
2026-09-19 10:55:34
(3 weeks ago)
2026-09-19T12:55:34.471370+02:00 coraza-spoa[262622]: [client "213.254.175.235"] Coraza: Access deni ...
show more
2026-09-19T12:55:34.471370+02:00 coraza-spoa[262622]: [client "213.254.175.235"] Coraza: Access denied (phase 2). Inbound Anomaly Score Exceeded (Total Score: 8)
show less
Hacking
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-19 10:50:39
(3 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-19 04:26:40
(3 weeks ago)
Attempt to scan vulnerabilities
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 00:17:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:17:29.685821 2026] [security2:error] [pid 6525:tid 6525] [client 213.254.175.235:35227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.169"] [uri "/library/.env"] [unique_id "aq3UmayKnJMA4KF14sw8JQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-19 00:09:10
(3 weeks ago)
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:04 217.194.210.152 GET /api/.env - 80 - 2 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-09-19 00:08:04 217.194.210.152 GET /api/.env - 80 - 213.254.175.235 HTTP/1.1 Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36 - 217.194.210.152 404 0 2 1503 234 127 - -
show less
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-18 15:19:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 11:19:37.571549 2026] [security2:error] [pid 26257:tid 26257] [client 213.254.175.235:26993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.6"] [uri "/api/.env"] [unique_id "aq1WiVdbykrn-dLvNYc-ZQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 12:57:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 08:56:55.287482 2026] [security2:error] [pid 18522:tid 18522] [client 213.254.175.235:41751] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.47"] [uri "/wp-admin/.env"] [unique_id "aq01F-olJwT7OpAzk3-HXgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 11:32:21
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:32:17.253724 2026] [security2:error] [pid 1124:tid 1135] [client 213.254.175.235:29821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/conf/.env"] [unique_id "aq0hQTHi_ey7GSglmDDylgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 07:27:51
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:27:19.541658 2026] [security2:error] [pid 27528:tid 27528] [client 213.254.175.235:31729] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.242"] [uri "/apps/.env"] [unique_id "aqzn12lSZiFACJWdoM4NoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-17 17:44:29
(3 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.env (Match: /.env)
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 10:45:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.254.175.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:45:02.348808 2026] [security2:error] [pid 31869:tid 31869] [client 213.254.175.235:30655] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.36"] [uri "/api/.env"] [unique_id "aqvErukNLkV6z9jv0yYyZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack