๐ณ๐ฑ
jjnxpct
2026-02-16 04:54:26
(3 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.env.save (Rule ID: 920440) - URL file extension is restricted by policy
show less
Hacking
SQL Injection
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-02-15 22:59:17
(3 months ago)
Auto-ban: >3000 req/min op 2026-02-15
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-02-15 12:46:44
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:46:38.365802 2026] [security2:error] [pid 2232:tid 2232] [client 45.3.40.230:20917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pathpa.org"] [uri "/wp/.git/config"] [unique_id "aZHALqfFeUxhR0dkE9ZIpwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 11:23:55
(3 months ago)
45.3.40.230 - - [15/Feb/2026:11:23:45 +0000] "GET /admin/.env HTTP/1.1" 403 2428 "-" "Mozilla/5.0 (W ...
show more
45.3.40.230 - - [15/Feb/2026:11:23:45 +0000] "GET /admin/.env HTTP/1.1" 403 2428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 07:09:28
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 02:09:23.499689 2026] [security2:error] [pid 405919:tid 405932] [client 45.3.40.230:42771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secondsundayseriesecc.org"] [uri "/.env"] [unique_id "aZFxI6-tSW-IIRHmX-C5eAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:58:09
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:58:01.733571 2026] [security2:error] [pid 22350:tid 22350] [client 45.3.40.230:37059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schlegelcreative.com"] [uri "/app/.env"] [unique_id "aZFgaS98swx6heWyQbPeYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-02-15 05:29:50
(3 months ago)
[Sun Feb 15 06:29:49.953627 2026] [security2:error] [pid 601510:tid 601531] [client 45.3.40.230:5014 ...
show more
[Sun Feb 15 06:29:49.953627 2026] [security2:error] [pid 601510:tid 601531] [client 45.3.40.230:50149] [client 45.3.40.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ohno.es"] [uri "/.git/config"] [unique_id "aZFZzYpFoyNi8-JdO-0rlwAAAFA"]
[Sun Feb 15 06:29:50.156586 2026] [security2:error] [pid 601510:tid 601526] [client 45.3.40.230:50149] [client 45.3.40.230] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-eva
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 05:26:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:26:27.529859 2026] [security2:error] [pid 18185:tid 18188] [client 45.3.40.230:31511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ogier.us"] [uri "/app/.git/config"] [unique_id "aZFZA_5BqIWf3sZml9F6lgAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:50:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:49:54.166503 2026] [security2:error] [pid 11846:tid 11846] [client 45.3.40.230:14379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sanvayu.com"] [uri "/site/.git/config"] [unique_id "aZFQcm6B3xv2kX5vCyv2qAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:59:10
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:59:07.293207 2026] [security2:error] [pid 14724:tid 14724] [client 45.3.40.230:50345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "potamus.net"] [uri "/.env.production"] [unique_id "aZFEixYHowixyaMGjx4rMgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-15 03:58:02
(3 months ago)
Bot / scanning and/or hacking attempts: GET /backend/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /. ...
show more
Bot / scanning and/or hacking attempts: GET /backend/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /.env.save HTTP/1.1, GET /app/.env HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /config/.env HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:32:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:32:39.694208 2026] [security2:error] [pid 15204:tid 15204] [client 45.3.40.230:47819] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rums-of-the-world.com"] [uri "/app/.git/config"] [unique_id "aZEwRzmvCSuzPifBwzFc2QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:27:37
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:27:33.087748 2026] [security2:error] [pid 17085:tid 17085] [client 45.3.40.230:19761] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pilotchristmascards.com"] [uri "/app/.env"] [unique_id "aZEhBcRH0qQhfljCse-mEgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:02:57
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.40.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:02:51.349788 2026] [security2:error] [pid 13505:tid 13505] [client 45.3.40.230:27981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockonevilrobots.com"] [uri "/new/.git/config"] [unique_id "aZEbO2UYPQf2gd2g1t2l4AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
oncord
2026-01-30 08:37:45
(4 months ago)
Form spam
Web Spam