๐บ๐ธ
TPI-Abuse
2026-06-01 08:12:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 04:12:30.575948 2026] [security2:error] [pid 2540:tid 2540] [client 2a02:4780:9:1024:0:614:eb00:1:47896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "glaswood.com"] [uri "/core/.env"] [unique_id "ah0-7uFLTNhlCO0PPy8IkAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-01 07:14:48
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-06-01 06:52:44
(2 days ago)
[AUTORAVALT][[01/06/2026 - 03:52:43 -03:00 UTC]
Attack from [2a02:4780:9:1024:0:614:eb00:1] Action: ...
show more
[AUTORAVALT][[01/06/2026 - 03:52:43 -03:00 UTC]
Attack from [2a02:4780:9:1024:0:614:eb00:1] Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/]
...
show less
Hacking
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-01 06:48:16
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-01 06:37:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 02:37:18.354708 2026] [security2:error] [pid 24049:tid 24049] [client 2a02:4780:9:1024:0:614:eb00:1:25878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sovereignstartups.com"] [uri "/member/.env"] [unique_id "ah0onsxCY6Wl-yIM2u-jbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-01 06:28:58
(2 days ago)
442 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-01 06:20:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 02:20:08.747692 2026] [security2:error] [pid 26444:tid 26472] [client 2a02:4780:9:1024:0:614:eb00:1:23036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grdsys.com"] [uri "/.env"] [unique_id "ah0kmEShUhKjQhNqaDbBHwAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 05:44:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 01:44:33.771399 2026] [security2:error] [pid 17508:tid 17508] [client 2a02:4780:9:1024:0:614:eb00:1:48922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vgalleria.com"] [uri "/core/.env"] [unique_id "ah0cQVBXeZNH7XbjYiH1bAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 05:05:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 01:05:07.207899 2026] [security2:error] [pid 18008:tid 18008] [client 2a02:4780:9:1024:0:614:eb00:1:42196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adrienberthaud.com"] [uri "/app/.env"] [unique_id "ah0TAxS5QfJjff55efkr9AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-01 04:55:37
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 02:52:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 22:52:12.356447 2026] [security2:error] [pid 20385:tid 20385] [client 2a02:4780:9:1024:0:614:eb00:1:22616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mikebenson.com"] [uri "/.env"] [unique_id "ahzz3KLvhMLAcKvqE5xqMwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chronos
2026-06-01 02:34:24
(2 days ago)
[AUTORAVALT][[31/05/2026 - 23:34:23 -03:00 UTC]
Attack from [2a02:4780:9:1024:0:614:eb00:1] Action: ...
show more
[AUTORAVALT][[31/05/2026 - 23:34:23 -03:00 UTC]
Attack from [2a02:4780:9:1024:0:614:eb00:1] Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various other software plugins/]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 01:29:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 21:29:40.720363 2026] [security2:error] [pid 31350:tid 31350] [client 2a02:4780:9:1024:0:614:eb00:1:55708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drlwr.com"] [uri "/core/.env"] [unique_id "ahzghGYS5g9VYFILSE9klgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-01 00:02:00
(2 days ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 23:52:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:9:1024:0:614:eb00:1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 19:52:34.377422 2026] [security2:error] [pid 18058:tid 18058] [client 2a02:4780:9:1024:0:614:eb00:1:31116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markrikey.com"] [uri "/core/.env"] [unique_id "ahzJwvpGTkP2Si1jxthzwgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack