๐บ๐ธ
TPI-Abuse
2026-06-30 09:53:59
(40 minutes ago)
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 05:53:50.374212 2026] [security2:error] [pid 17293:tid 17293] [client 43.229.61.53:53125] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grandriverhomes.com"] [uri "/.env.test"] [unique_id "akOSLp7defMqnNBCK3y45QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 08:47:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 04:47:15.965836 2026] [security2:error] [pid 15343:tid 15348] [client 43.229.61.53:59251] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.expozium.annybelle.org"] [uri "/.env.dev"] [unique_id "akOCk2JSf45NgIlfzgrhSAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-30 08:00:53
(2 hours ago)
WordPress config file probe
Web App Attack
Anonymous
2026-06-30 07:59:14
(2 hours ago)
(caddyscan) Scanner path probe from 43.229.61.53 (AU/Australia/43.229.61.53): 5 in the last 3600 sec ...
show more
(caddyscan) Scanner path probe from 43.229.61.53 (AU/Australia/43.229.61.53): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 43.229.61.53 - - [30/Jun/2026:07:59:08 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 43.229.61.53 - - [30/Jun/2026:07:59:09 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 43.229.61.53 - - [30/Jun/2026:07:59:09 +0000] "GET /.env.test.local HTTP/1.1"
[REDACTED] 200 2627 43.229.61.53 - - [30/Jun/2026:07:59:11 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 43.229.61.53 - - [30/Jun/2026:07:59:12 +0000] "GET /src/.env HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
Site.eu
2026-06-30 07:34:09
(3 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-06-30 07:28:24
(3 hours ago)
Probing\(5\) HTTP Ports
...
Bad Web Bot
Web App Attack
Anonymous
2026-06-30 07:06:36
(3 hours ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=78
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-30 07:03:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 03:03:05.791712 2026] [security2:error] [pid 16025:tid 16025] [client 43.229.61.53:56183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tommckee.tunabay.com"] [uri "/.env.local"] [unique_id "akNqKaBbyJm6IKld2iXJigAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 06:47:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:47:41.621576 2026] [security2:error] [pid 30942:tid 30942] [client 43.229.61.53:40409] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enselme.com"] [uri "/.env"] [unique_id "akNmjSdKIwpMtlU-3cjgYAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-06-30 06:32:09
(4 hours ago)
Bad_requests
Bad Web Bot
๐ท๐บ
DZBOT
2026-06-30 06:26:56
(4 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-06-30 06:01:34
(4 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-201)
show less
Hacking
๐ฉ๐ช
mondor.ro
2026-06-30 05:53:39
(4 hours ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 43.229.61.53, Reason:[ ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 43.229.61.53, Reason:[(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (AU/Australia/43.229.61.53): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-30 05:52:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 43.229.61.53 (43.229.61.53): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 01:52:06.160120 2026] [security2:error] [pid 31893:tid 31893] [client 43.229.61.53:58679] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthearodgers.com"] [uri "/.env.staging"] [unique_id "akNZhmEdNH9T7Wape2BVaAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Axel
2026-06-30 05:47:36
(4 hours ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.example ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.env.example Server: UK-01
show less
Web App Attack
Hacking
SQL Injection