πΊπΈ
TPI-Abuse
2026-08-31 13:14:42
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 09:14:37.979222 2026] [security2:error] [pid 13167:tid 13167] [client 2a09:2dc2:0:54ff:::45620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthonyanimalclinic.net"] [uri "/.env.local.example"] [unique_id "apV-PZ59_antDlxJFZe_mQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 12:59:04
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:58:57.859109 2026] [security2:error] [pid 29735:tid 29735] [client 2a09:2dc2:0:54ff:::54230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antcanada.com"] [uri "/.env.old"] [unique_id "apV6kTqMjfra4RGG4z_Y6wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-30 22:04:01
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-29.
show less
Web App Attack
SSH
Hacking
π¬π§
foxxelabs
2026-08-30 20:26:12
(17 hours ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exp ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.env | Project: anseo | Reason(s): Known exploit path: /.env | User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 15:42:18
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 11:42:08.511145 2026] [security2:error] [pid 28679:tid 28679] [client 2a09:2dc2:0:54ff:::55252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alkahf.xyz"] [uri "/.env.development.swp"] [unique_id "apRPUO2aOMBPwNlkQPwKEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 00:37:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 20:36:56.550230 2026] [security2:error] [pid 10745:tid 10745] [client 2a09:2dc2:0:54ff:::48216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adoniahenterprises.com"] [uri "/goober_.htaccess.preinstall"] [unique_id "apN7KHqKOwPGIMMg2FgudgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
Saec
2026-08-29 23:57:02
(1 day ago)
Jarvis auto-ban: Honeypot /.env.bak via admin.saec.ovh [UA] ASN:Virtual Systems LLC
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 21:10:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 17:10:26.887224 2026] [security2:error] [pid 1529270:tid 1529410] [client 2a09:2dc2:0:54ff:::56738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adambarnard.com"] [uri "/.env"] [unique_id "apNKwpbwcN4_b7s3YiBFmAAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 11:17:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:17:37.087793 2026] [security2:error] [pid 25573:tid 25573] [client 2a09:2dc2:0:54ff:::56634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accinternational.net"] [uri "/.env.old"] [unique_id "apK_0WY3J3ViAsVa39Q92QAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 07:30:04
(2 days ago)
| [Dangerous/Ukraine] Aggressive IP 2a09:2dc2:0:54ff:: (~30 hits). Type: DoS Defender- Web server 40 ...
show more
| [Dangerous/Ukraine] Aggressive IP 2a09:2dc2:0:54ff:: (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-29 03:24:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:24:43.549681 2026] [security2:error] [pid 4498:tid 4498] [client 2a09:2dc2:0:54ff:::53294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaabft.com"] [uri "/.env.dev.dist"] [unique_id "apJQ-w5wf61Wm3Nm-AB6hgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-08-28 09:12:18
(3 days ago)
backup exfil on 405.today/backup.tar.gz β WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 07:21:10
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:2dc2:0:54ff:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:21:03.627891 2026] [security2:error] [pid 17911:tid 17911] [client 2a09:2dc2:0:54ff:::55618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||360.visitbyblos.com|F|2"] [data ".properties.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "360.visitbyblos.com"] [uri "/application.properties.bak"] [unique_id "apE238TtAfbgoc7ZSJ4IFAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack