๐บ๐ธ
TPI-Abuse
2026-07-23 14:05:49
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 10:05:40.125116 2026] [security2:error] [pid 710825:tid 710825] [client 85.239.230.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avaliantlife.com"] [uri "/.env"] [unique_id "amIftNbR5LxSVqoN3lSgIQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 12:01:26
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฌ๐ง
consul.to
2026-07-23 11:22:55
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
Smish
2026-07-23 07:20:18
(7 hours ago)
HONEYPOT HIT --> Fail2ban time=1784791216 log=2026-07-23T08:20:16+01:00 ip=85.239.230.212 host=as210 ...
show more
HONEYPOT HIT --> Fail2ban time=1784791216 log=2026-07-23T08:20:16+01:00 ip=85.239.230.212 host=as210667.net method=GET uri="/.env" status=404 ua="python-requests/2.32.3" ref="-" rid=23d3915cd0973c0fdfee6f4560a52bc9
show less
Web App Attack
Anonymous
2026-07-23 04:00:10
(10 hours ago)
Scanning/Probing activity detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
VanKoh
2026-07-22 19:47:21
(18 hours ago)
85.239.230.212 - - [22/Jul/2026:13:47:19 -0600] "GET /.env HTTP/1.1" 301 162 "-" "python-requests/2. ...
show more
85.239.230.212 - - [22/Jul/2026:13:47:19 -0600] "GET /.env HTTP/1.1" 301 162 "-" "python-requests/2.32.3"
85.239.230.212 - - [22/Jul/2026:13:47:19 -0600] "POST / HTTP/1.1" 301 162 "-" "python-requests/2.32.3"
85.239.230.212 - - [22/Jul/2026:13:47:20 -0600] "GET /?%3Cplay%3Ewithme%3C/%3E HTTP/1.1" 301 162 "-" "python-requests/2.32.3"
...
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:00:30
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:00:21.766860 2026] [security2:error] [pid 19381:tid 19381] [client 85.239.230.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easy-byte.net"] [uri "/.env"] [unique_id "amETRbLnuu0LWGjpS1_W4gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 17:49:53
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): ...
show more
(mod_security) mod_security (id:210492) triggered by 85.239.230.212 (vmi3403686.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 13:49:49.118342 2026] [security2:error] [pid 1839140:tid 1839140] [client 85.239.230.212:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "amECvYZB64X3fIa8X9W6_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-22 17:45:04
(20 hours ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐จ๐ญ
blinx
2026-07-22 16:27:20
(21 hours ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ต๐พ
armandosaucedo.me
2026-07-22 15:21:47
(23 hours ago)
Threat Intelligence via ARMTI, Web Attack: GET /.env
Web App Attack
๐ซ๐ท
Jimbo67
2026-07-22 11:08:48
(1 day ago)
Cloudflare WAF: 1 hits in 30s | action=block | abuse=confirmed_abuse | categories=21 | rule_id=0189a ...
show more
Cloudflare WAF: 1 hits in 30s | action=block | abuse=confirmed_abuse | categories=21 | rule_id=0189a8c2c2ab4a60bc709bad14577d18 | URIs=/.env | confidence=0.95
show less
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-07-22 10:31:30
(1 day ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /.env | Pays: US | UA: python-requests/2.32.3
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 10:06:23
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-22 09:34:51
(1 day ago)
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 1 security event. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack