πΊπΈ
TPI-Abuse
2026-07-27 19:18:39
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:18:33.380669 2026] [security2:error] [pid 4007751:tid 4007751] [client 2a09:bac5:9443:3af::5e:57:19624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petland.app.lucid-events.com"] [uri "/.env"] [unique_id "amevCWx_lbz7xR37YRCniwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 18:55:31
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:55:28.114285 2026] [security2:error] [pid 20741:tid 20741] [client 2a09:bac5:9443:3af::5e:57:23276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.microbooty.com"] [uri "/.env"] [unique_id "amepoBCHryYTiKqrqE_-wAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-07-27 18:53:56
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 18:21:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:21:39.308272 2026] [security2:error] [pid 2315032:tid 2315032] [client 2a09:bac5:9443:3af::5e:57:62226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.evelowerealtor.com"] [uri "/.env"] [unique_id "amehsyqGtxU6s37meICPfQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2026-07-27 18:12:47
(1 hour ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 17:58:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:58:24.901995 2026] [security2:error] [pid 3155:tid 3155] [client 2a09:bac5:9443:3af::5e:57:27176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.technoware-lb.com"] [uri "/.env"] [unique_id "amecQIAbTAMA8qcTvnLa-AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 09:58:06
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:57:58.375849 2026] [security2:error] [pid 1382196:tid 1382196] [client 2a09:bac5:9443:3af::5e:57:55038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.charityholidaycards.com"] [uri "/wp-config.php.old"] [unique_id "amcrphV_qGorQP8hTAo2iwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
thilo
2026-07-25 12:07:29
(2 days ago)
Probe for vulnerabilities. Path attempted: /.env.production
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 11:27:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 07:27:11.992964 2026] [security2:error] [pid 18016:tid 18016] [client 2a09:bac5:9443:3af::5e:57:38652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.thecalls.net"] [uri "/.env"] [unique_id "amSdj1SsMiLXq-KOm_M4dAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 11:10:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 07:10:01.815083 2026] [security2:error] [pid 1478179:tid 1478179] [client 2a09:bac5:9443:3af::5e:57:31790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aticom.es"] [uri "/.env"] [unique_id "amSZieL_InMGTE7lLEWycgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 10:30:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:30:06.060607 2026] [security2:error] [pid 770724:tid 770724] [client 2a09:bac5:9443:3af::5e:57:43036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jiveturkeyband.com"] [uri "/.env"] [unique_id "amSQLgTxqQFFhaE1JTIBBAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 09:53:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:53:09.077668 2026] [security2:error] [pid 2147223:tid 2147223] [client 2a09:bac5:9443:3af::5e:57:57692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purebinary.cathrynn.com"] [uri "/.env.staging"] [unique_id "amSHhY7qIWI5cdxmvKcy8AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±πΉ
NotACaptcha
2026-07-25 09:23:58
(2 days ago)
webserver:443 [25/Jul/2026] "GET /service-account.json HTTP/1.1" 404 5677 "-" "Mozilla/5.0 (Macinto ...
show more
webserver:443 [25/Jul/2026] "GET /service-account.json HTTP/1.1" 404 5677 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
webserver:443 [25/Jul/2026] "GET /.aws/credentials HTTP/1.1" 404 463 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
webserver:443 [25/Jul/2026] "GET /.env HTTP/1.1" 404 5677 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
webserver:443 [25/Jul/2026] "GET /credentials.json HTTP/1.1" 404 5677 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
webserver:443 [25/Jul/2026] "GET /serviceAccountKey.json HTTP/1.1" 404 5677 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 09:01:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:01:50.140623 2026] [security2:error] [pid 749878:tid 749878] [client 2a09:bac5:9443:3af::5e:57:12630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.idahostem.org"] [uri "/.env"] [unique_id "amR7froauNB-O1jSnCWsZgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 08:37:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9443:3af::5e:57 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 04:37:11.908743 2026] [security2:error] [pid 84168:tid 84168] [client 2a09:bac5:9443:3af::5e:57:20302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "datebynumber.smogsandiego.com"] [uri "/.env"] [unique_id "amR1tztYQHNGvvdR_wLz1QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack