๐บ๐ธ
octageeks.com
2026-01-14 05:06:45
(6 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
mnsf
2026-01-14 01:05:13
(6 months ago)
Too many Status 40X (37)
Scanning/Probing (44)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 14:30:31
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 09:30:27.130806 2026] [security2:error] [pid 21722:tid 21722] [client 3.85.36.146:64968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cuul.co"] [uri "/.env"] [unique_id "aWZXAwbsy5Y0xD2Qaod11wAAAHM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
pantanet
2026-01-13 13:36:14
(6 months ago)
Fail2Ban nginx jail: nginx-badbots
Port Scan
Hacking
Brute-Force
๐บ๐ธ
ambor
2026-01-13 13:28:11
(6 months ago)
Honeypot triggered on tcpdata.com - Attempted to access /.env (config_file_probe). User-Agent: Mozil ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /.env (config_file_probe). User-Agent: Mozilla/5.0 (EnvHunter/1.0)
show less
Web App Attack
๐บ๐ธ
TheJoy
2026-01-13 12:37:00
(6 months ago)
unauthorized url access
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 11:17:10
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 06:17:06.541528 2026] [security2:error] [pid 7096:tid 7096] [client 3.85.36.146:61009] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zavijava.net"] [uri "/.env"] [unique_id "aWYpsh3weQs0qrBGSX7puAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
billfor
2026-01-13 10:15:33
(6 months ago)
3.85.36.146 - - [13/Jan/2026:05:15:21 -0500] "GET /.env HTTP/1.1" 403 0 "-" "Mozilla/5.0 (EnvHunter/ ...
show more
3.85.36.146 - - [13/Jan/2026:05:15:21 -0500] "GET /.env HTTP/1.1" 403 0 "-" "Mozilla/5.0 (EnvHunter/1.0)"
3.85.36.146 - - [13/Jan/2026:05:15:26 -0500] "GET /.env.local HTTP/1.1" 403 0 "-" "Mozilla/5.0 (EnvHunter/1.0)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 09:40:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 04:40:29.751842 2026] [security2:error] [pid 524:tid 524] [client 3.85.36.146:49345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wethepeoplealliance.org"] [uri "/.env"] [unique_id "aWYTDWf8LOGm01gQVNleDwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 09:14:34
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 04:14:29.990955 2026] [security2:error] [pid 1913642:tid 1913642] [client 3.85.36.146:58228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alternatievemedia.com"] [uri "/.env"] [unique_id "aWYM9VnuP-fbKxTxRfMpbQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 08:54:12
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 03:54:04.842653 2026] [security2:error] [pid 5061:tid 5061] [client 3.85.36.146:53385] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.env"] [unique_id "aWYILCIAcsS3aDvqqDW3qwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-01-13 08:07:36
(6 months ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-01-13 08:03:25
(6 months ago)
(mod_security) mod_security triggered on hostname [redacted] 3.85.36.146 (US/United States/ec2-3-85- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.85.36.146 (US/United States/ec2-3-85-36-146.compute-1.amazonaws.com)
show less
SQL Injection
๐ซ๐ท
LRob
2026-01-13 08:00:03
(6 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-13 07:51:52
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.85.36.146 (ec2-3-85-36-146.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jan 13 02:51:48.751149 2026] [security2:error] [pid 7062:tid 7062] [client 3.85.36.146:58013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singleslidestrategy.com"] [uri "/.env"] [unique_id "aWX5lIrmc6VVk71hkaBUVwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack