๐ณ๐ฑ
homeshowdomain.nl
2026-05-22 21:59:14
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-21.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
brightenfield
2026-05-22 09:41:28
(2 weeks ago)
Web App Attack
Web App Attack
๐บ๐ธ
mnsf
2026-05-22 09:05:32
(2 weeks ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-05-22 07:15:36
(2 weeks ago)
dot file probe
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-22 05:29:44
(2 weeks ago)
Try to access /.env
Web App Attack
๐ฉ๐ช
gadix
2026-05-22 05:05:49
(2 weeks ago)
[22/May/2026:07:05:44.874434 +0200] ag_kKEg1HywSOwplStv4lgAAAAE 91.239.78.138 46464 127.0.0.1 7081
[ ...
show more
[22/May/2026:07:05:44.874434 +0200] ag_kKEg1HywSOwplStv4lgAAAAE 91.239.78.138 46464 127.0.0.1 7081
[22/May/2026:07:05:45.203408 +0200] ag_kKShFT1fE8WVMviwc0gAAAAQ 91.239.78.138 46466 127.0.0.1 7081
[22/May/2026:07:05:45.352484 +0200] ag_kKRmzZNeSB0_cdbqWBQAAAAM 91.239.78.138 46468 127.0.0.1 7081
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-05-22 03:30:19
(2 weeks ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-05-22 03:17:02
(2 weeks ago)
Bot / scanning and/or hacking attempts: GET /core/.env HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env. ...
show more
Bot / scanning and/or hacking attempts: GET /core/.env HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.example HTTP/1.1, GET /debug/default/view HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 02:38:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 22:38:24.636933 2026] [security2:error] [pid 29629:tid 29629] [client 91.239.78.138:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kidswithcamerasmovie.com"] [uri "/.env.local"] [unique_id "ag_BoOoDhBT-JphJuF3FsAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 01:28:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 21:28:47.491874 2026] [security2:error] [pid 11667:tid 11667] [client 91.239.78.138:40215] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerrywelt.com"] [uri "/.env.production"] [unique_id "ag-xT3u_Yb0FBOiQN8p73AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-22 00:45:33
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-21 22:00:48
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-05-21
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-21 18:33:37
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 14:33:31.872697 2026] [security2:error] [pid 18973:tid 19036] [client 91.239.78.138:47835] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "joblackwell.com"] [uri "/.env"] [unique_id "ag9P-0abQ-WrKn3A25MxvgAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 15:15:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 11:15:10.462052 2026] [security2:error] [pid 20487:tid 20487] [client 91.239.78.138:54591] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jdhunterlaw.com"] [uri "/.env"] [unique_id "ag8hfsqhRfs2TwzJ1vgxzgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 14:26:02
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.138 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 10:25:57.343234 2026] [security2:error] [pid 2575:tid 2575] [client 91.239.78.138:44797] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janton.com"] [uri "/.env"] [unique_id "ag8V9caE7MR6Y4pJkBAJvAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack