πΊπΈ
TPI-Abuse
2026-06-07 07:19:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 03:19:18.432087 2026] [security2:error] [pid 26530:tid 26530] [client 82.29.185.29:25904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "castedguy.com"] [uri "/admin/.env"] [unique_id "aiUbdrb1SGuzzIuhW7ZsHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-06-07 06:36:07
(3 hours ago)
Web vulnerability probing: /laravel/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 06:00:14
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 02:00:07.993579 2026] [security2:error] [pid 26923:tid 26923] [client 82.29.185.29:63272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deluxeexpress.com"] [uri "/api/.env.save"] [unique_id "aiUI55DFF0Pw3IgU_068XwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 03:19:08
(6 hours ago)
(caddyscan) Scanner path probe from 82.29.185.29 (GB/United Kingdom/-): 5 in the last 3600 secs; Por ...
show more
(caddyscan) Scanner path probe from 82.29.185.29 (GB/United Kingdom/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 82.29.185.29 - - [07/Jun/2026:03:19:06 +0000] "GET /.env.save HTTP/1.1"
[REDACTED] 200 2627 82.29.185.29 - - [07/Jun/2026:03:19:06 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 82.29.185.29 - - [07/Jun/2026:03:19:06 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 82.29.185.29 - - [07/Jun/2026:03:19:06 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 82.29.185.29 - - [07/Jun/2026:03:19:06 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-06-07 03:12:26
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 23:12:21.740744 2026] [security2:error] [pid 11026:tid 11026] [client 82.29.185.29:24184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laurenandfrank.com"] [uri "/core/.env.save"] [unique_id "aiThlVuOa1O5qqNEshH9PwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-07 03:05:39
(6 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 02:46:28
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 82.29.185.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 22:46:21.568376 2026] [security2:error] [pid 10117:tid 10117] [client 82.29.185.29:21246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markthwaite.com"] [uri "/.env.save"] [unique_id "aiTbfb3LpwVmD_iILtQtCgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Matthew Ping
2026-06-07 02:45:01
(7 hours ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
π©πͺ
Vegascosmetics
2026-06-07 00:06:43
(9 hours ago)
Kingcopy(AI-IDS) Report: IP automatically blocked after obfuscated encoding. Vegas Security System
DDoS Attack
Hacking
Bad Web Bot
π«π·
dynamix
2026-06-07 00:01:41
(9 hours ago)
Multiple WAF Violations
Web App Attack
πΈπͺ
vaia.cloud
2026-06-06 23:26:01
(10 hours ago)
trying wp-login.php/xmlrpc.php 36 times in 1 minutes
Brute-Force
Web App Attack
π«π·
masterguru
2026-06-06 23:20:25
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
π²πΎ
Rizzy
2026-06-06 22:30:35
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π¨π
Origon
2026-06-06 22:15:42
(11 hours ago)
http-sensitive-files - IP: 82.29.185.29 - time="2026-06-07T00:15:41+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 82.29.185.29 - time="2026-06-07T00:15:41+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 82.29.185.29 (GB/47583) : 4h ban on Ip 82.29.185.29" module=db
show less
Web App Attack
π©πͺ
Ba-Yu
2026-06-06 22:13:35
(11 hours ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack