๐บ๐ธ
TPI-Abuse
2026-07-24 17:05:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:05:47.288776 2026] [security2:error] [pid 3932861:tid 3932861] [client 2a09:bac1:76a0:480::11:19b:10984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emisoni.com"] [uri "/.env"] [unique_id "amOba7GX36A9DTAaZgIy9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:41:27
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:41:22.224801 2026] [security2:error] [pid 788273:tid 788273] [client 2a09:bac1:76a0:480::11:19b:58762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.printedweddingribbons.com"] [uri "/.env"] [unique_id "amOVsnq8EwkYVLaEItt0CgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-24 16:28:54
(1 month ago)
CrowdSec: crowdsecurity/http-probing | req: /serviceAccountKey.json | 11 distinct paths | UA: Mozill ...
show more
CrowdSec: crowdsecurity/http-probing | req: /serviceAccountKey.json | 11 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 Edg/147.0.0.0
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:19:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:19:52.682533 2026] [security2:error] [pid 1553790:tid 1553790] [client 2a09:bac1:76a0:480::11:19b:53436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mathiasaspelin.com"] [uri "/.env"] [unique_id "amOQqA691dePSjPv8ce8gAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
flarehawk.com
2026-07-24 16:03:25
(1 month ago)
Observed suspicious traffic by Flarehawk security analytics. Report source: https://flarehawk.com.
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:41:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:40:58.310020 2026] [security2:error] [pid 24957:tid 24957] [client 2a09:bac1:76a0:480::11:19b:58812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pnwdso.org"] [uri "/.env"] [unique_id "amOHimyu_AFIWkf_SeePOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
boxed-it
2026-07-24 15:26:54
(1 month ago)
GET /.env (Tarpitted for 10m, wasted 35.27kB)
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-24 15:24:17
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 15:05:05
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:49:06
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac1:76a0:480::11:19b (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:49:02.391821 2026] [security2:error] [pid 1728013:tid 1728013] [client 2a09:bac1:76a0:480::11:19b:22238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eliteregenmed.com"] [uri "/.env"] [unique_id "amN7XsqZc20-kZfSiGDwCAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack