πΊπΈ
TPI-Abuse
2026-07-28 10:06:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:06:52.329517 2026] [security2:error] [pid 607873:tid 607873] [client 2a09:bac5:9442:3af::5e:87:33414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.possmartterminal.com"] [uri "/.env"] [unique_id "amh_PCpWR9qwtnCaXgOh2gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Major Hostility
2026-07-27 13:26:21
(2 days ago)
"GET /service-account.json HTTP/1.1" 404
"GET /.aws/config HTTP/1.1" 404
"GET /.env.production HTTP/ ...
show more
"GET /service-account.json HTTP/1.1" 404
"GET /.aws/config HTTP/1.1" 404
"GET /.env.production HTTP/1.1" 404
"GET /.env.backup HTTP/1.1" 404
"GET /.env.dev HTTP/1.1" 404
"GET /.openclaw/openclaw.json HTTP/1.1" 404
"GET /client_secret.json HTTP/1.1" 404
"GET /firebase-service-account.json HTTP/1.1" 404
show less
Web App Attack
π©πͺ
neckaralb-admin.de
2026-07-27 12:46:38
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
4server
2026-07-27 12:12:43
(2 days ago)
[MonJul2714:12:40.3342672026][security2:error][pid2942791:tid2942850][client2a09:bac5:9442:3af::5e:8 ...
show more
[MonJul2714:12:40.3342672026][security2:error][pid2942791:tid2942850][client2a09:bac5:9442:3af::5e:87:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"hdcadvisory.ch\"][uri\"/.aws/credentials\"][unique_id\"amdLOMlW4iApEr_Qi-HTnwAAAFY\"]
show less
Port Scan
Brute-Force
Web App Attack
π³π±
e.fierstra
2026-07-27 02:55:13
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-07-27 02:54:36
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (X11; ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64; rv:150.0) Gecko/20100101 Firefox/150.0
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 02:29:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 22:29:30.727583 2026] [security2:error] [pid 3239794:tid 3239794] [client 2a09:bac5:9442:3af::5e:87:44844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.diepeveen.com"] [uri "/.env"] [unique_id "ambCircBJ2Fhtfvh6viGOQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-26 22:26:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 18:26:36.782392 2026] [security2:error] [pid 3519153:tid 3519153] [client 2a09:bac5:9442:3af::5e:87:18454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toomuchcaffeine.net"] [uri "/.env"] [unique_id "amaJnJs73KaIfj1zCr6SygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2026-07-26 21:56:45
(3 days ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 20:02:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:02:04.625250 2026] [security2:error] [pid 28913:tid 28913] [client 2a09:bac5:9442:3af::5e:87:29656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.akronpartybuses.com"] [uri "/.env.local"] [unique_id "amUWPKgslr0yMTsZX4SL7wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 23:17:23
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:17:19.796484 2026] [security2:error] [pid 773489:tid 773489] [client 2a09:bac5:9442:3af::5e:87:30662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.peggyannjones.us"] [uri "/.env"] [unique_id "amPyf1EfyYzwa2ysvJG3eQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 22:57:51
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 18:57:47.215030 2026] [security2:error] [pid 13439:tid 13439] [client 2a09:bac5:9442:3af::5e:87:35836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.ofertasdetrabajosyempleos.com"] [uri "/.env"] [unique_id "amPt68vht8g8nRX9kZvwbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-07-24 19:28:00
(5 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (Wind ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-24 12:00:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9442:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:00:10.104653 2026] [security2:error] [pid 3567970:tid 3567970] [client 2a09:bac5:9442:3af::5e:87:47584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.casaniagara.com.mx"] [uri "/.env.local"] [unique_id "amNTyirPxY-pdvXxrNt5iwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-07-23 21:59:44
(6 days ago)
Probing websites for vulnerabilities
Web App Attack