Anonymous
2026-07-01 04:35:36
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-08 09:48:06
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:48:02.763297 2026] [security2:error] [pid 28569:tid 28569] [client 2a02:4780:27:1846:0:90d:a52c:1:45892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wardellbrown.com"] [uri "/dev/.env"] [unique_id "aiaP0iXZNL9KThEVq19PuAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
john doe
2026-06-08 05:33:34
(2 months ago)
SentinelBot: Env File Hunting (score: 76)
Bad Web Bot
๐ฉ๐ช
pscriptos
2026-06-08 02:48:20
(2 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-06-08 02:39:37
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-06-08 02:18:01
(2 months ago)
[redacted] 2a02:4780:27:1846:0:90d:a52c:1 - - [08/Jun/2026:03:17:59 +0100] "GET /api/.env HTTP/1.1" ...
show more
[redacted] 2a02:4780:27:1846:0:90d:a52c:1 - - [08/Jun/2026:03:17:59 +0100] "GET /api/.env HTTP/1.1" 302 1570 0/62669 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" [redacted] 2a02:4780:27:1846:0:90d:a52c:1 - - [08/Jun/2026:03:17:59 +0100] "GET /core/.env HTTP/1.1" 302 1538 0/82191 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" [redacted] 2a02:4780:27:1846:0:90d:a52c:1 - - [08/Jun/2026:03:17:59 +0100] "GET /app/.env HTTP/1.1" 302 1538 0/98501 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" [redacted] 2a02:4780:27:1846:0:90d:a52c:1 - - [08/Jun/2026:03:17:59 +0100] "GET /dev/.env HTTP/1.1" 302 1538 0/105385 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 01:47:02
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 21:46:55.255111 2026] [security2:error] [pid 14001:tid 14001] [client 2a02:4780:27:1846:0:90d:a52c:1:48098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baker15.com"] [uri "/dev/.env"] [unique_id "aiYfD45ZhIorGLb-_IIkgQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 01:23:57
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 21:23:51.043932 2026] [security2:error] [pid 8797:tid 8797] [client 2a02:4780:27:1846:0:90d:a52c:1:41828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnehrlich.org"] [uri "/dev/.env"] [unique_id "aiYZp69tO3GIIIuvfMJ2pwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-07 22:06:31
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-06.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-07 21:39:20
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:39:12.593270 2026] [security2:error] [pid 30786:tid 30786] [client 2a02:4780:27:1846:0:90d:a52c:1:21572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sveum.net"] [uri "/member/.env"] [unique_id "aiXlABxXxARyVhCi9iI4WwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 21:10:44
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:10:36.247642 2026] [security2:error] [pid 690:tid 690] [client 2a02:4780:27:1846:0:90d:a52c:1:44968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webserviceswest.com"] [uri "/backend/.env"] [unique_id "aiXeTJbYRVTSU-P5J2G-ngAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 18:20:53
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 14:20:48.331420 2026] [security2:error] [pid 962:tid 1053] [client 2a02:4780:27:1846:0:90d:a52c:1:32312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wintechltd.com"] [uri "/backend/.env"] [unique_id "aiW2gISfp0zwvZNY8h25MQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 15:43:32
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 11:43:25.171614 2026] [security2:error] [pid 10098:tid 10098] [client 2a02:4780:27:1846:0:90d:a52c:1:23356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingscruff.com"] [uri "/laravel/.env"] [unique_id "aiWRnbFf7Vze7lQlsGaP4wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 15:25:51
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in ...
show more
(mod_security) mod_security (id:949110) triggered by 2a02:4780:27:1846:0:90d:a52c:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 11:25:45.801550 2026] [security2:error] [pid 1113:tid 1113] [client 2a02:4780:27:1846:0:90d:a52c:1:45912] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "bluerockdragon.com"] [uri "/backend/.env"] [unique_id "aiWNeViU-F5D8jMukybZsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
conseilgouz
2026-06-07 14:25:38
(2 months ago)
doe-17 : Block hidden directories=>/admin/.env(/)
Hacking