๐ฉ๐ช
grassau.com
2026-07-25 17:57:16
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 64.95.11.191 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 64.95.11.191 (US/United States/Texas/Dallas/-)
show less
Bad Web Bot
๐ฎ๐น
Inartis
2026-07-25 17:43:46
(2 days ago)
64.95.11.191 - - [25/Jul/2026:19:43:45 +0200] "GET /.env HTTP/1.1" 403 5029 "-" "Mozilla/5.0 AppleWe ...
show more
64.95.11.191 - - [25/Jul/2026:19:43:45 +0200] "GET /.env HTTP/1.1" 403 5029 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.1; +https://openai.com/gptbot"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 15:23:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 11:23:36.163347 2026] [security2:error] [pid 1098630:tid 1098630] [client 64.95.11.191:33744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.palmerattaway.com.intothebigempty.com"] [uri "/.env"] [unique_id "amTU-GeX0lJMGCxNYooszgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
billyw0nka
2026-07-25 09:45:36
(3 days ago)
pattern: .env
Hacking
๐ฆ๐บ
screwlooseit.com.au
2026-07-25 09:43:36
(3 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 09:26:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:26:05.734372 2026] [security2:error] [pid 162506:tid 162506] [client 64.95.11.191:53692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.velocitymechcrm.com.jbcllcnet.com"] [uri "/.env"] [unique_id "amSBLYuIP5pHKH5gCrckVAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 08:42:34
(3 days ago)
fail2ban: apache-secrets-scan jail (1 hits in 2419200s) on skipper
Web App Attack
Hacking
๐ฑ๐ป
garmtech.com
2026-07-25 01:30:14
(3 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:37:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:36:58.312935 2026] [security2:error] [pid 5546:tid 5546] [client 64.95.11.191:55434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nerdwizards.toyz.net"] [uri "/.env"] [unique_id "amQFKu94SsdNR9ulEWMp7wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-25 00:06:51
(3 days ago)
Abuse Detected (10)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 23:51:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 64.95.11.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:51:36.309334 2026] [security2:error] [pid 1124490:tid 1124490] [client 64.95.11.191:53094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mikethenomad.com.michaelkivisto.com"] [uri "/.env"] [unique_id "amP6iMnD0Qe9mzvxmUsDlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 20:50:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
4server
2026-07-24 20:45:59
(3 days ago)
[FriJul2422:45:57.7546212026][security2:error][pid3641500:tid3641587][client64.95.11.191:0]ModSecuri ...
show more
[FriJul2422:45:57.7546212026][security2:error][pid3641500:tid3641587][client64.95.11.191:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\^0\$\"against\"REQUEST_HEADERS:Content-Length\"required.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"88\"][id\"392301\"][rev\"8\"][msg\"Atomicorp.comWAFRules:RequestContainingContent\,butMissingContent-Typeheader\"][severity\"NOTICE\"][tag\"no_ar\"][hostname\"www.buletti-panettoni.ch\"][uri\"/\"][unique_id\"amPPBenMMJyuqUWwzVcwBwAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-07-24 14:06:02
(4 days ago)
Blocked: Reason='Suspicious traffic score=70 (review-based detection)'; Requests=4
Hacking
๐ฆ๐น
Renรฉ Hickersberger
2026-07-24 14:01:37
(4 days ago)
malicious bot detected: violations="ignored-robots-policy"; user_agent="Mozilla/5.0 AppleWebKit/537. ...
show more
malicious bot detected: violations="ignored-robots-policy"; user_agent="Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.1; +https://openai.com/gptbot"
show less
Bad Web Bot