๐บ๐ธ
TPI-Abuse
2026-08-27 23:09:10
(45 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:09:03.603940 2026] [security2:error] [pid 31284:tid 31302] [client 2607:5300:205:200::adf7:34320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "potterpuppetpals.com"] [uri "/.env"] [unique_id "apDDjzTix-dvQiU5oPqwvAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:53:56
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:949110) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:53:50.472428 2026] [security2:error] [pid 14852:tid 14852] [client 2607:5300:205:200::adf7:52000] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "experimentalscene.com"] [uri "/.env"] [unique_id "apC__iGJMpam4Ab8HpG5fgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-27 18:16:10
(5 hours ago)
2026/08/27 18:16:05 [error] 2898860#2898860: *527402950 access forbidden by rule, client: 2607:5300: ...
show more
2026/08/27 18:16:05 [error] 2898860#2898860: *527402950 access forbidden by rule, client: 2607:5300:205:200::adf7, server: fastcredit.net.ua, request: "GET /.env HTTP/2.0", host: "fastcredit.net.ua"
2026/08/27 18:16:07 [error] 2898859#2898859: *527399930 access forbidden by rule, client: 2607:5300:205:200::adf7, server: fastcredit.net.ua, request: "GET /.env.bak HTTP/2.0", host: "fastcredit.net.ua"
2026/08/27 18:16:08 [error] 2898859#2898859: *527399930 access forbidden by rule, client: 2607:5300:205:200::adf7, server: fastcredit.net.ua, request: "GET /.env.backup HTTP/2.0", host: "fastcredit.net.ua"
...
show less
Web App Attack
Anonymous
2026-08-27 17:50:05
(6 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-27 14:17:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:16:53.705394 2026] [security2:error] [pid 18201:tid 18201] [client 2607:5300:205:200::adf7:33950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexgitlin.com"] [uri "/.env"] [unique_id "apBG1a6PDtAFZSI0D8Mg_gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 13:25:36
(10 hours ago)
[27/Aug/2026:16:25:34 +0300] 17878371349.606409 2607:5300:205:200::adf7 38058 2a01:4f8:202:41d3::2 4 ...
show more
[27/Aug/2026:16:25:34 +0300] 17878371349.606409 2607:5300:205:200::adf7 38058 2a01:4f8:202:41d3::2 443
[27/Aug/2026:16:25:35 +0300] 178783713537.459213 2607:5300:205:200::adf7 38068 2a01:4f8:202:41d3::2 443
show less
Web App Attack
๐ฉ๐ช
todix
2026-08-27 12:20:44
(11 hours ago)
Web App Attack Exploid from 2607:5300:205:200::adf7
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:39:09
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:39:01.291727 2026] [security2:error] [pid 29492:tid 29492] [client 2607:5300:205:200::adf7:58772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n3fjp.com"] [uri "/.env"] [unique_id "ao-VNTKX3ARvj-wf0lLtIgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 23:57:20
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:57:14.829829 2026] [security2:error] [pid 22143:tid 22143] [client 2607:5300:205:200::adf7:42422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compassionfatigue.org"] [uri "/.env"] [unique_id "ao99WufI3JKaF8YO8izlmQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 22:09:41
(1 day ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /.env.bak
Web App Attack
๐ซ๐ท
dynamix
2026-08-26 20:24:49
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 16:54:28
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-08-26 16:54 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-26 16:31:09
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 16:26:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.c ...
show more
(mod_security) mod_security (id:210492) triggered by 2607:5300:205:200::adf7 (vps-4d0f6a51.vps.ovh.ca): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:25:59.055423 2026] [security2:error] [pid 30666:tid 30666] [client 2607:5300:205:200::adf7:48774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marveldirectory.com"] [uri "/.env"] [unique_id "ao8Tl-dM-ed8MuG5xlbtywAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-08-26 15:57:40
(1 day ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking