๐ง๐พ
lns.bz
2026-06-30 07:23:45
(15 minutes ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 07:03:40
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 03:03:33.177999 2026] [security2:error] [pid 12523:tid 12523] [client 43.99.103.238:48774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalpozzolanassociation.org"] [uri "/.env.test"] [unique_id "akNqRaI4m8RDRG6633HXIQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-30 06:52:08
(47 minutes ago)
43.99.103.238 - - [30/Jun/2026:08:52:08 +0200] "GET /.env.bak HTTP/1.1" 403 2363 "-" "Mozilla/5.0 (W ...
show more
43.99.103.238 - - [30/Jun/2026:08:52:08 +0200] "GET /.env.bak HTTP/1.1" 403 2363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran)"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 06:48:00
(51 minutes ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:47:53.975900 2026] [security2:error] [pid 24350:tid 24350] [client 43.99.103.238:34104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/api/.env"] [unique_id "akNmmRiYJHjbScfVtsPzvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 06:19:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:19:38.272681 2026] [security2:error] [pid 7047:tid 7047] [client 43.99.103.238:55676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janesoffice.com"] [uri "/.env.bak"] [unique_id "akNf-kEThSK0pV_wjpkb6AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-30 06:08:50
(1 hour ago)
[TueJun3008:08:46.8731582026][security2:error][pid2076256:tid2076406][client43.99.103.238:0]ModSecur ...
show more
[TueJun3008:08:46.8731582026][security2:error][pid2076256:tid2076406][client43.99.103.238:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpu-services.ch.81-17-25-250.cpanel.site\"][uri\"/.env.dev\"][unique_id\"akNdblwNB_M702xW4tXx-QAAABI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 04:52:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 00:52:34.016557 2026] [security2:error] [pid 21584:tid 21584] [client 43.99.103.238:57298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "evolinc.com"] [uri "/web/.env"] [unique_id "akNLkrwGBQZzYWrnv-oabAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 07:10:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 03:10:09.733980 2026] [security2:error] [pid 19259:tid 19347] [client 43.99.103.238:44042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.silverrat.com"] [uri "/.env.template"] [unique_id "akIaUR-NK_6poR7Zg2WCJwAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 07:29:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 03:29:43.979628 2026] [security2:error] [pid 3038:tid 3038] [client 43.99.103.238:45008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yun-san.com"] [uri "/web/.env"] [unique_id "akDNZ__8eAdnUZpg9rZDEAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-27 10:05:29
(2 days ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 02:56:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 22:56:42.668082 2026] [security2:error] [pid 13778:tid 13778] [client 43.99.103.238:60602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bigbandrockparty.com.jazzclubla.com"] [uri "/.env"] [unique_id "aj876rtvSJ4QNHYOclQ5hQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-26 22:02:57
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-26 21:31:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 43.99.103.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 17:31:45.936003 2026] [security2:error] [pid 10572:tid 10572] [client 43.99.103.238:60306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mediatvplus.com"] [uri "/.env.local"] [unique_id "aj7vwR5cUtzBTokNcSl67wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-06-26 16:23:19
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.env | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-06-25 23:39:34
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack