๐บ๐ธ
myagent.site
2026-04-04 09:10:26
(3 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-04-04 09:01:17
(3 months ago)
(mod_security) mod_security (id:949110) triggered by 91.234.7.9 (UA/Ukraine/dedicated.vsys.host): N ...
show more
(mod_security) mod_security (id:949110) triggered by 91.234.7.9 (UA/Ukraine/dedicated.vsys.host): N in the last X secs
show less
Web App Attack
๐บ๐ธ
Matthew Ping
2026-04-04 08:45:01
(3 months ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-04-03 22:01:50
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-02.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
oisecnet
2026-04-03 21:02:12
(3 months ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-04-03. 8 requests from this I ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-04-03. 8 requests from this IP.
show less
Brute-Force
Web App Attack
SSH
๐บ๐ธ
mnsf
2026-04-03 19:06:12
(3 months ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐ณ๐ฑ
SKIPREPORTER
2026-04-03 18:09:00
(3 months ago)
Automated probe targeting sensitive configuration files.
IP attempted to access:
GET /.env.stagi ...
show more
Automated probe targeting sensitive configuration files.
IP attempted to access:
GET /.env.staging
User-Agent:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
This pattern is consistent with vulnerability scanning for exposed environment files (.env).
Request was blocked. No successful access.
show less
Port Scan
Web App Attack
Hacking
๐บ๐ธ
SLSLLC
2026-04-03 07:46:23
(3 months ago)
91.234.7.9 - - [03/Apr/2026:07:46:22 +0000] "GET /.env.staging HTTP/2.0" 403 1927 "-" "Mozilla/5.0 ( ...
show more
91.234.7.9 - - [03/Apr/2026:07:46:22 +0000] "GET /.env.staging HTTP/2.0" 403 1927 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 07:10:21
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 03:10:17.302351 2026] [security2:error] [pid 9006:tid 9006] [client 91.234.7.9:57365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.order.thereddoorlounge.com"] [uri "/.env.backup"] [unique_id "ac9n2aJkuqEysO-_FRA_JwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 04:21:31
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 00:21:27.075542 2026] [security2:error] [pid 553:tid 553] [client 91.234.7.9:55167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.new.desertrosedoves.com"] [uri "/.env.development"] [unique_id "ac9AR5xOV43cl6xLMhe4FgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 03:54:07
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 23:54:03.204066 2026] [security2:error] [pid 11552:tid 11552] [client 91.234.7.9:39341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.navarreunited.nysasports.com"] [uri "/.env.development"] [unique_id "ac852_dSoJMGXcm2vC7mGwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-04-03 02:29:28
(3 months ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 02:28:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 91.234.7.9 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 22:28:17.875365 2026] [security2:error] [pid 7390:tid 7390] [client 91.234.7.9:54607] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.movil.mpservice.com.sv"] [uri "/.env.staging"] [unique_id "ac8lwWBYSAB2oi2aJUwYugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-04-03 01:10:39
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
andypiper
2026-04-03 01:02:43
(3 months ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack