๐บ๐ธ
TPI-Abuse
2026-06-07 05:33:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:33:30.651555 2026] [security2:error] [pid 9287:tid 9287] [client 76.13.75.179:24012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "echelonts.com"] [uri "/app/.env"] [unique_id "aiUCqjYSdZqL-GRIcSwKgQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 05:04:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 01:04:26.420289 2026] [security2:error] [pid 14385:tid 14385] [client 76.13.75.179:57878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thunderbirdchimes.com"] [uri "/api/.env"] [unique_id "aiT72hw6n1GoYPAoFKiOnwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-07 01:44:56
(7 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
Anonymous
2026-06-07 01:40:01
(7 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐ฌ๐ง
sc user
2026-06-06 23:16:15
(9 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ธ
paulo.apoloni
2026-06-06 22:50:27
(10 hours ago)
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /dev/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macin ...
show more
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /dev/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /app/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /api/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /laravel/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
76.13.75.179 - - [06/Jun/2026:19:50:26 -0300] "GET /member/.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chro
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 21:56:35
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 17:56:28.148573 2026] [security2:error] [pid 12332:tid 12332] [client 76.13.75.179:52424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intervinum.net"] [uri "/.env"] [unique_id "aiSXjFr4PPaFmbhp3IBcFwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2026-06-06 21:14:38
(12 hours ago)
Web App Attack
Web App Attack
Anonymous
2026-06-06 20:27:01
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /index.php HTTP/1.1, GET /member/.env HTTP/1.1, GET /dev ...
show more
Bot / scanning and/or hacking attempts: GET /index.php HTTP/1.1, GET /member/.env HTTP/1.1, GET /dev/.env HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /app/.env HTTP/1.1, GET /.env HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-06 19:45:39
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐จ๐ญ
ALPHANET
2026-06-06 19:36:19
(13 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 19:31:04
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:31:00.179606 2026] [security2:error] [pid 17992:tid 17992] [client 76.13.75.179:60932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deanfountain.com"] [uri "/dev/.env"] [unique_id "aiR1dA8m62LeTPK3n2HdEwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-06 18:33:31
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐จ๐ญ
Origon
2026-06-06 18:16:42
(14 hours ago)
http-sensitive-files - IP: 76.13.75.179 - time="2026-06-06T20:16:41+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 76.13.75.179 - time="2026-06-06T20:16:41+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 76.13.75.179 (US/47583) : 4h ban on Ip 76.13.75.179" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 17:46:19
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 76.13.75.179 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 13:46:12.488560 2026] [security2:error] [pid 20990:tid 20990] [client 76.13.75.179:30178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ardath.net"] [uri "/dev/.env"] [unique_id "aiRc5LhU-4v8YH8rzjMEBgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack