Anonymous
2026-05-09 03:07:02
(3 weeks ago)
Excessive 404 Traffic Wordpress
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-05-08 20:53:14
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-08 18:04:58
(3 weeks ago)
(mod_security) mod_security (id:949110) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 14:04:50.251503 2026] [security2:error] [pid 4940:tid 4940] [client 62.93.179.140:60276] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "armstrongenv.com"] [uri "/.env"] [unique_id "af4lwt1DfS-DX030b5ONbQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-08 17:07:46
(3 weeks ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 15:57:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 11:57:44.102701 2026] [security2:error] [pid 22832:tid 22832] [client 62.93.179.140:54728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "appsdips.com"] [uri "/.env"] [unique_id "af4H-E213doMcjdHlz4PTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 15:42:03
(3 weeks ago)
Bot / scanning and/or hacking attempts: [0/0] read: stream 0, , GET /.env HTTP/2.0
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-05-08 15:39:24
(3 weeks ago)
758 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 15:17:50
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 11:17:46.149585 2026] [security2:error] [pid 2365:tid 2365] [client 62.93.179.140:60517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aperturecontrols.com"] [uri "/.env"] [unique_id "af3-mjnwzpYOSKYH-q280QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-08 15:05:50
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
ParaBug
2026-05-08 14:50:16
(3 weeks ago)
62.93.179.140 - - [08/May/2026:16:50:16 +0200] "GET /.env HTTP/2.0" 301 434 "-" "Mozilla/5.0 (iPhone ...
show more
62.93.179.140 - - [08/May/2026:16:50:16 +0200] "GET /.env HTTP/2.0" 301 434 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_7 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) FxiOS/148.0 Mobile/15E148 Safari/605.1.15"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 14:48:00
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:47:57.322848 2026] [security2:error] [pid 25055:tid 25055] [client 62.93.179.140:51981] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anthonyvanstyn.com"] [uri "/.env"] [unique_id "af33nTOS6frYsDRcKPJvZwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 14:29:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:28:59.017486 2026] [security2:error] [pid 3110:tid 3110] [client 62.93.179.140:50668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ankitoner.com"] [uri "/.env"] [unique_id "af3zK4SrvEhoYlEY-myNSQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 14:11:25
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 62.93.179.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 10:11:17.578167 2026] [security2:error] [pid 14360:tid 14360] [client 62.93.179.140:63036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anenchantingevening.com"] [uri "/.env"] [unique_id "af3vBa0fxCtjiSkSY3IevwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-08 14:09:03
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-05-08 14:00:03
(3 weeks ago)
trolling for resource vulnerabilities
Web App Attack