๐บ๐ธ
TPI-Abuse
2026-10-04 21:45:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:45:50.065282 2026] [security2:error] [pid 9419:tid 9432] [client 39.105.103.64:60399] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "careofsouls.org"] [uri "/core/.env"] [unique_id "asLJDuDIypFDXDhTw3LNNAAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Feelautom
2026-10-04 21:17:46
(6 days ago)
[FeelAutom Auto-Ban] PathScan: /.env.production (Score: 200)
Port Scan
Anonymous
2026-10-04 20:13:18
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-04 18:39:37
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 14:39:32.123931 2026] [security2:error] [pid 21963:tid 21963] [client 39.105.103.64:51933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armandselmwoodpark.com"] [uri "/.env.save"] [unique_id "asKdZB4hq3-rlCaQDtShqwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 17:40:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 13:40:37.753585 2026] [security2:error] [pid 16860:tid 16860] [client 39.105.103.64:52373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamroomrecording.com"] [uri "/backup/.env"] [unique_id "asKPlQztdTipCgsMvxwfcwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-04 17:11:07
(6 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 16:11:22
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 12:11:14.237074 2026] [security2:error] [pid 8439:tid 8439] [client 39.105.103.64:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswithcamerasmovie.com"] [uri "/public/.env"] [unique_id "asJ6ornWYo3cTis6eLrh8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 15:34:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 11:34:05.197375 2026] [security2:error] [pid 15864:tid 15864] [client 39.105.103.64:50141] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plugsinc.com"] [uri "/app/.env"] [unique_id "asJx7fSMX5Glffe61vBa5AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 11:32:02
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 07:31:58.389741 2026] [security2:error] [pid 9963:tid 9963] [client 39.105.103.64:56159] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brazilianbottom.com"] [uri "/app/.env"] [unique_id "asI5LryTfeOiISV2-M07eQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 11:05:04
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 07:04:56.305665 2026] [security2:error] [pid 2095137:tid 2095153] [client 39.105.103.64:61353] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yakagroup.org"] [uri "/api/.env"] [unique_id "asIy2Gqg80l1edMXOGXmYQAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-04 11:01:44
(6 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
Epimetheus
2026-10-04 10:06:30
(6 days ago)
Unauthorized access attempts:
[GET] /vendor/.env
[GET] /.env.save
[GET] /core/.env
[GET] /backup/.e ...
show more
Unauthorized access attempts:
[GET] /vendor/.env
[GET] /.env.save
[GET] /core/.env
[GET] /backup/.env
[GET] /public/.env
[GET] /.env.prod
[GET] /.env.local
[GET] /.env.backup
[GET] /app/.env
[GET] /.env.bak
[GET] /files/.env
[GET] /.env
[GET] /.env.old
[GET] /.env.production
[GET] /api/.env
[GET] /config/.env
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 09:57:33
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 39.105.103.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 05:57:27.521021 2026] [security2:error] [pid 28698:tid 28698] [client 39.105.103.64:63683] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnrods.com"] [uri "/.env.prod"] [unique_id "asIjByFZvgRfeJ94jS9_dQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-04 09:00:22
(6 days ago)
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 39.105.103.64 (CN/China/-): 2 in ...
show more
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 39.105.103.64 (CN/China/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ต๐ฑ
sefinek.net
2026-10-04 08:46:56
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from CN.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /app/.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot