๐ซ๐ท
COMAITE
2026-07-24 19:41:29
(3 days ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:03:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:02:58.152535 2026] [security2:error] [pid 382361:tid 382361] [client 217.217.255.131:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swarnar.com"] [uri "/.env.bak"] [unique_id "amOMsiWWB6jy-ogNRnvRZAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-07-23 03:52:49
(5 days ago)
URL Probing: /.env
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-22 23:34:11
(5 days ago)
20 attempts against mh-misbehave-ban on sedna
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jcbriar
2026-07-22 23:08:27
(5 days ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 21:58:22
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 17:58:17.825504 2026] [security2:error] [pid 2112220:tid 2112220] [client 217.217.255.131:37038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stkm.com"] [uri "/.env.bak"] [unique_id "amE8-ZecsrXR7w53etiriwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 20:26:41
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:26:37.111790 2026] [security2:error] [pid 1602537:tid 1602537] [client 217.217.255.131:49556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "steambalancing.com"] [uri "/.env.bak"] [unique_id "amEnfVZqfwHh00wBcXerxwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-22 20:10:49
(5 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 217.217.255.131 (SG/Singapore/vmi331 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 217.217.255.131 (SG/Singapore/vmi3316766.contaboserver.net): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:50:54
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:50:47.229276 2026] [security2:error] [pid 1528369:tid 1528369] [client 217.217.255.131:56444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewarttaylor.com"] [uri "/.env.bak"] [unique_id "amEfF6YwJPR31FAhD45_AQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-22 17:59:21
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-07-22 12:41:57
(5 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-07-22 09:41:44
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 217.217.255.131 (SG/Singapore/vmi331676 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 217.217.255.131 (SG/Singapore/vmi3316766.contaboserver.net)
show less
SQL Injection
๐ณ๐ด
jad-abuse
2026-07-22 08:59:37
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: env_probe, source_backup, phpunit_rce. Observed by 1 sensor(s); 72 hits.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 08:30:37
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 04:30:33.742989 2026] [security2:error] [pid 9026:tid 9026] [client 217.217.255.131:50430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srossi.net"] [uri "/.env.bak"] [unique_id "amB_qQFAjAf5gFEZeqd9aAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 07:46:00
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 217.217.255.131 (vmi3316766.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 03:45:53.508541 2026] [security2:error] [pid 1667845:tid 1667845] [client 217.217.255.131:36904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srosa.com"] [uri "/.env.bak"] [unique_id "amB1Mdeu-LIUvE02pfuxcwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack