๐ง๐ช
cmbplf
2026-08-09 05:29:56
(1 month ago)
203 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 23:25:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:24:56.578954 2026] [security2:error] [pid 2586580:tid 2586580] [client 2a09:bac5:9443:3af::5e:45:46218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.daveroozendaal.com"] [uri "/.env"] [unique_id "amfoyI5sdHKQWZXCWO7ynwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 23:06:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:06:25.159056 2026] [security2:error] [pid 22559:tid 22559] [client 2a09:bac5:9443:3af::5e:45:13972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lmga.net"] [uri "/.env.production"] [unique_id "amfkcV8RF1B1HRdYCvVtRAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:46:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:46:11.256343 2026] [security2:error] [pid 938641:tid 938641] [client 2a09:bac5:9443:3af::5e:45:57724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.joescherzi.com"] [uri "/.env.local"] [unique_id "amffswDd_9S_vxJNI7Hh-gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 02:40:41
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 22:40:37.421724 2026] [security2:error] [pid 3911698:tid 3911698] [client 2a09:bac5:9443:3af::5e:45:47580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artaquiouno4.ipostsocialmedia.com"] [uri "/.env"] [unique_id "ambFJdoL1djjJoNKz9oglAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-26 22:20:23
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-07-26 22:19:57
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 21:58:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 17:58:09.816107 2026] [security2:error] [pid 3590306:tid 3590306] [client 2a09:bac5:9443:3af::5e:45:64262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "islanublarproperties.thinksite.net"] [uri "/.env"] [unique_id "amaC8b3rzlgu6Gq4w_OPCQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 21:33:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 17:33:34.715159 2026] [security2:error] [pid 2974979:tid 2974979] [client 2a09:bac5:9443:3af::5e:45:43378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crescentcitycafe.org"] [uri "/.env"] [unique_id "amZ9Lug6qsS90D_YE_ZI3gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-07-24 04:35:06
(1 month ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-24 04:27:40
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:00:01
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:59:56.162286 2026] [security2:error] [pid 2926495:tid 2926495] [client 2a09:bac5:9443:3af::5e:45:28210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "haroparke.chevronparkett.com"] [uri "/.env.production"] [unique_id "amLVLJ_7KbItzi5r_Ju4bQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-23 02:36:34
(1 month ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 02:25:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 22:25:07.583280 2026] [security2:error] [pid 1854264:tid 1854264] [client 2a09:bac5:9443:3af::5e:45:42254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.player-care.us"] [uri "/.env.production"] [unique_id "amF7g8H_O19T-ctzSYrubQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 00:56:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:45 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:56:52.579094 2026] [security2:error] [pid 4984:tid 4984] [client 2a09:bac5:9443:3af::5e:45:58604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bikinitweets.com"] [uri "/.env.staging"] [unique_id "amFm1CqnMp2bAJh5YdquSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack