๐ฆ๐บ
advena
2025-10-03 13:30:57
(10 months ago)
79.136.242.80 (AS56981 TOMSK-AS) was intercepted at 2025-10-03T13:18:17Z after violating WAF directi ...
show more
79.136.242.80 (AS56981 TOMSK-AS) was intercepted at 2025-10-03T13:18:17Z after violating WAF directive: country. Pre-cautionary/corrective action applied: block.
show less
Web Spam
Hacking
Brute-Force
Web App Attack
Anonymous
2025-10-03 09:22:06
(10 months ago)
Infected user bad webscan
Exploited Host
Anonymous
2025-10-03 03:24:24
(10 months ago)
Infected user bad webscan
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-10-01 16:36:35
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:36:31.283032 2025] [security2:error] [pid 733:tid 733] [client 79.136.242.80:50925] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theneighborswindow.com"] [uri "/.env"] [unique_id "aN1Yj350J1igWFZ2pZCgogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 16:12:15
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 12:12:09.406981 2025] [security2:error] [pid 30111:tid 30174] [client 79.136.242.80:62288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mabinogion.info"] [uri "/.env"] [unique_id "aN1S2RH4YjaIRtXIcLCOmgAAAgQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2025-10-01 16:03:06
(10 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 13:48:02
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 09:47:56.767890 2025] [security2:error] [pid 1346:tid 1346] [client 79.136.242.80:56416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matterofbritain.com"] [uri "/.env"] [unique_id "aN0xDIl4fxROlGv50xIvCQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-01 11:27:06
(10 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 10:52:44
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 06:52:36.546723 2025] [security2:error] [pid 19157:tid 19157] [client 79.136.242.80:54219] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "passwordresearch.com"] [uri "/.env"] [unique_id "aN0H9ImqfaGquZazu5SApwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 08:29:52
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 04:29:48.619802 2025] [security2:error] [pid 29878:tid 29878] [client 79.136.242.80:55976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-practical-pionus.com"] [uri "/.env"] [unique_id "aNzmfLpz6guSLPs7b6IjvwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 07:45:38
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 03:45:33.362228 2025] [security2:error] [pid 4551:tid 4551] [client 79.136.242.80:54626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "petiteplaisanceconservationfund.org"] [uri "/.env"] [unique_id "aNzcHUR1q5gWaCZFAH39IQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 02:32:54
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 22:32:48.192665 2025] [security2:error] [pid 19131:tid 19131] [client 79.136.242.80:49663] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curriculum-web.com"] [uri "/.env"] [unique_id "aNyS0OXRWbET2blEz2SIfwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-01 01:11:02
(10 months ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐ซ๐ฎ
TrafficAnalyser
2025-09-30 15:49:42
(10 months ago)
Probing "GET /.env HTTP/1.1"
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-30 15:30:07
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 79.136.242.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 30 11:30:01.825266 2025] [security2:error] [pid 5719:tid 5719] [client 79.136.242.80:55992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "talamancareserve.com"] [uri "/.env"] [unique_id "aNv3eQoCjer2MdF_VyggpwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack