๐ซ๐ฎ
YF
2026-10-02 17:01:05
(1 week ago)
Environment file probe
Web App Attack
๐ฉ๐ช
hidemail.app
2026-10-02 15:48:01
(1 week ago)
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto ...
show more
Automated scan for exposed config/secret files and known web exploits (e.g. /.env, RCE probes); auto-banned by fail2ban.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 15:38:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:38:12.430487 2026] [security2:error] [pid 5464:tid 5464] [client 2a02:4780:28:bf40::1:64384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "westernmassaa.net"] [uri "/.env"] [unique_id "ar_P5AtkKjdpkY56cp7BXAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:44:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:44:20.529002 2026] [security2:error] [pid 19753:tid 19753] [client 2a02:4780:28:bf40::1:51704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.closedfortheseason.com"] [uri "/.env"] [unique_id "ar_DRNEb4f_b5ckwVPyGtAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-02 14:22:41
(1 week ago)
Cloudflare WAF: Request Path: /.env Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 ...
show more
Cloudflare WAF: Request Path: /.env Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Action: block Source: firewallCustom ASN Description: Hostinger International Limited Country: FR Method: GET Timestamp: 2026-10-02T14:22:41Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:57:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:57:25.528865 2026] [security2:error] [pid 15983:tid 15983] [client 2a02:4780:28:bf40::1:49888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.somehand.com"] [uri "/.env"] [unique_id "ar-4Rah_eTMyJxdvvboPuwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:37:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:36:55.933501 2026] [security2:error] [pid 23928:tid 23928] [client 2a02:4780:28:bf40::1:60010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "briancastle.com"] [uri "/.env"] [unique_id "ar-zd15kzLZXmq7w-s4LnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 13:30:29
(1 week ago)
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW ...
show more
Secret file probe | method: GET | path: /.env | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 | 2026-10-02 13:30 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:05:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:05:49.829582 2026] [security2:error] [pid 2741:tid 2741] [client 2a02:4780:28:bf40::1:55366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecorinthians.info"] [uri "/.env"] [unique_id "ar-sLR1sDypPHuXXD85_BQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-02 12:32:44
(1 week ago)
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 2a02:4780:28:bf40::1 (FR/France/ ...
show more
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 2a02:4780:28:bf40::1 (FR/France/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐จ๐ฆ
Anytech
2026-10-02 12:00:08
(1 week ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 11:15:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:15:13.129905 2026] [security2:error] [pid 30506:tid 30506] [client 2a02:4780:28:bf40::1:64271] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingscruff.com"] [uri "/.env"] [unique_id "ar-SQdEPoc6kjii10SmodQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:21:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:21:35.331176 2026] [security2:error] [pid 29265:tid 29265] [client 2a02:4780:28:bf40::1:57423] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caferutadelaseda.com"] [uri "/.env"] [unique_id "ar-Fr4ixEVAuqKa2WqVTCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:44:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:44:14.337372 2026] [security2:error] [pid 8379:tid 8379] [client 2a02:4780:28:bf40::1:53394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recetabook.com"] [uri "/.env"] [unique_id "ar987qJ4wv3uP46qDpIYYgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:23:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:28:bf40::1 (srv2013610.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:23:51.930745 2026] [security2:error] [pid 20467:tid 20467] [client 2a02:4780:28:bf40::1:56858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hanabritgermanshepherds.com"] [uri "/.env"] [unique_id "ar94J0x1XGz1wLCCPgRXAgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack