๐บ๐ธ
TPI-Abuse
2026-07-29 17:00:32
(9 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:00:27.961192 2026] [security2:error] [pid 21225:tid 21225] [client 2a09:bac5:9447:3af::5e:87:41170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblioteca.navarrete.ws"] [uri "/.env.local"] [unique_id "amoxqzQR2PwtVijC-b5jEwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-29 16:45:05
(25 minutes ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 16:12:52
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 12:12:46.856817 2026] [security2:error] [pid 1944111:tid 1944111] [client 2a09:bac5:9447:3af::5e:87:49512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinghydraulics.com"] [uri "/.env"] [unique_id "amomflEmL8YdIFDYqnLRbAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 02:32:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:32:26.263205 2026] [security2:error] [pid 3702861:tid 3702861] [client 2a09:bac5:9447:3af::5e:87:26212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.hotpay.co"] [uri "/.env"] [unique_id "amLOuqPncBi2gKwTrN5cTgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 02:13:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 22:13:16.974581 2026] [security2:error] [pid 3825582:tid 3825582] [client 2a09:bac5:9447:3af::5e:87:55696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.francisfell.com"] [uri "/.env"] [unique_id "amLKPAJ_W1s2eWLqpnE-ngAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 06:32:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 02:32:08.340596 2026] [security2:error] [pid 2094734:tid 2094734] [client 2a09:bac5:9447:3af::5e:87:38178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thomaschemicals.com"] [uri "/.env"] [unique_id "al8SaN2iaX78NfhyRAab4wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-18 12:07:02
(1 week ago)
Automated web scanner. Requested suspicious paths: /service-account.json. UTC: 2026-07-18 11:19:31.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 10:57:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 06:56:56.068740 2026] [security2:error] [pid 5191:tid 5191] [client 2a09:bac5:9447:3af::5e:87:34936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.drgracetomastolentino.com"] [uri "/.env.staging"] [unique_id "altb-OLoyaNw1XycmJrp8AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 10:01:42
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:9447:3af::5e:87 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 06:01:33.807265 2026] [security2:error] [pid 14990:tid 14990] [client 2a09:bac5:9447:3af::5e:87:42250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||elevese.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elevese.com"] [uri "/trace.axd"] [unique_id "aldaffi8yzcX82mtciEI8QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-10 22:00:24
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-09.
show less
Web App Attack
SSH
Hacking