๐บ๐ธ
TPI-Abuse
2026-07-30 10:34:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 06:34:33.433999 2026] [security2:error] [pid 2639086:tid 2639104] [client 2a09:bac1:7680:460::5e:76:28732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fevini.com"] [uri "/.env.production"] [unique_id "amsouSngh9081BbXoxGvIQAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-29 02:17:48
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 16:31:44
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ช๐ธ
alferez
2026-07-23 11:35:22
(1 week ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 10:59:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:59:26.687382 2026] [security2:error] [pid 3774319:tid 3774319] [client 2a09:bac1:7680:460::5e:76:22898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cienmalos.com"] [uri "/.env"] [unique_id "amH0DoDJmlMi_mew2OtyBQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-21 05:38:43
(1 week ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (X11; ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64; rv:149.0) Gecko/20100101 Firefox/149.0
show less
Hacking
๐ฌ๐ง
gws-hostmaster
2026-07-21 04:29:13
(1 week ago)
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;Restricted File Access Att ...
show more
ModSecurity OWASP CRS (Anomaly Score: 10): Restricted File Access Attempt;Restricted File Access Attempt: AI Coding Assistant Artifact;URL file extension is restricted by policy;
show less
Web App Attack
๐ฉ๐ช
4server
2026-07-21 04:12:24
(1 week ago)
[TueJul2106:12:18.9840942026][security2:error][pid2135218:tid2135231][client2a09:bac1:7680:460::5e:7 ...
show more
[TueJul2106:12:18.9840942026][security2:error][pid2135218:tid2135231][client2a09:bac1:7680:460::5e:76:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webmail.gmint.ch\"][uri\"/.env.bak\"][unique_id\"al7xogXoQGZ5kbMSrCvpHAAAAQo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-07-21 03:49:59
(1 week ago)
[redacted] 2a09:bac1:7680:460::5e:76 - - [21/Jul/2026:04:49:57 +0100] "GET /.env HTTP/1.1" 302 6758 ...
show more
[redacted] 2a09:bac1:7680:460::5e:76 - - [21/Jul/2026:04:49:57 +0100] "GET /.env HTTP/1.1" 302 6758 0/51172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36" [redacted] 2a09:bac1:7680:460::5e:76 - - [21/Jul/2026:04:49:58 +0100] "GET /.aws/config HTTP/1.1" 302 1539 0/87495 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Mobile/15E148 Safari/604.1"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 03:41:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 23:41:00.866724 2026] [security2:error] [pid 1749559:tid 1749559] [client 2a09:bac1:7680:460::5e:76:56302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.allcostaricarentals.com"] [uri "/.env"] [unique_id "al7qTPQfbO19U2OAL9FBfgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-21 03:12:04
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 03:09:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 23:09:20.068901 2026] [security2:error] [pid 29530:tid 29530] [client 2a09:bac1:7680:460::5e:76:17618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "i-spose.com"] [uri "/.env"] [unique_id "al7i4CGrbakbZegqd7KknQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 02:06:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 22:06:50.040368 2026] [security2:error] [pid 10524:tid 10524] [client 2a09:bac1:7680:460::5e:76:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.enperth.org"] [uri "/.env"] [unique_id "al7UOhjbQTH40loxuQ0xSAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-21 01:20:57
(1 week ago)
(modsecurity) srv101 ModSecurity 2a09:bac1:7680:460::5e:76 (US/United States/-): 10 in the last 3600 ...
show more
(modsecurity) srv101 ModSecurity 2a09:bac1:7680:460::5e:76 (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 01:16:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:7680:460::5e:76 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 21:16:30.776160 2026] [security2:error] [pid 2172473:tid 2172473] [client 2a09:bac1:7680:460::5e:76:31618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.themedecade.com"] [uri "/.env"] [unique_id "al7IbrMi9kVGpzlntsfMNQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack