๐บ๐ธ
TPI-Abuse
2026-10-07 20:14:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:14:45.934573 2026] [security2:error] [pid 19343:tid 19363] [client 2a02:4780:95:5e2d::1:50243] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quantumgaze.com"] [uri "/.env"] [unique_id "asaoNc0kTpAtvw3BCojNZwAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-07 19:54:04
(6 hours ago)
127 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
๐ฉ๐ช
Reinhard
2026-10-07 19:34:47
(6 hours ago)
Parameter or path manipulation, hacking. /.env.bak
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-07 19:28:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:28:11.079893 2026] [security2:error] [pid 23308:tid 23308] [client 2a02:4780:95:5e2d::1:57114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "r-390a.net"] [uri "/.env"] [unique_id "asadS5C2I-Pd1V2EzqQI1QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-10-07 19:22:44
(6 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
Anonymous
2026-10-07 19:12:49
(6 hours ago)
[07/Oct/2026:22:12:49 +0300] 17914003698.745897 2a02:4780:95:5e2d::1 51803 2a01:4f8:202:41d3::2 443
...
show more
[07/Oct/2026:22:12:49 +0300] 17914003698.745897 2a02:4780:95:5e2d::1 51803 2a01:4f8:202:41d3::2 443
[07/Oct/2026:22:12:49 +0300] 179140036965.940009 2a02:4780:95:5e2d::1 51813 2a01:4f8:202:41d3::2 443
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:58:11
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:58:04.555777 2026] [security2:error] [pid 9828:tid 9828] [client 2a02:4780:95:5e2d::1:63671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proprocessor.com"] [uri "/.env.production"] [unique_id "asaWPC7upgiGeahurMcZ1gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-10-07 18:34:40
(7 hours ago)
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /wp-config.php HTTP/1.1" 403 8041 "-" "Mo ...
show more
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /wp-config.php HTTP/1.1" 403 8041 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /config/.env HTTP/1.1" 403 8040 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /.env.local HTTP/1.1" 403 8040 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /.env.old HTTP/1.1" 403 8040 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:4780:95:5e2d::1 - - [07/Oct/2026:18:34:39 +0000] "GET /.env.production HTTP/1.1" 403 8039 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
Web App Attack
Exploited Host
๐ซ๐ท
gavrielpiperno
2026-10-07 18:24:10
(7 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 18:19:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:19:16.414807 2026] [security2:error] [pid 28865:tid 28865] [client 2a02:4780:95:5e2d::1:51761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garon.us"] [uri "/.env"] [unique_id "asaNJIDJ9uFzbgZuOwCL9AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-07 18:15:04
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
tinect
2026-10-07 18:11:17
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
ipblock.com
2026-10-07 18:10:00
(7 hours ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
stechusa
2026-10-07 13:24:14
(12 hours ago)
[Askari] | country=CY | ASN=Hostinger International Limited | Behavior: Only requesting one page typ ...
show more
[Askari] | country=CY | ASN=Hostinger International Limited | Behavior: Only requesting one page type, HTTP/1.1 over TLS, Concurrent page load during attack, Rotating user agents, HTTP/1.1 only
show less
Bad Web Bot
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 14:24:05
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:95:5e2d::1 (srv1715918.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 10:23:57.867892 2026] [security2:error] [pid 17445:tid 17445] [client 2a02:4780:95:5e2d::1:40185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cs-mall.com"] [uri "/.env.local"] [unique_id "aqK9fSHWzLVo7PJADO-aHwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack