๐ณ๐ฑ
homeshowdomain.nl
2026-05-20 22:04:04
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-19.
show less
Web App Attack
SSH
Hacking
๐ซ๐ฎ
mnazibo
2026-05-20 11:00:04
(2 weeks ago)
Date: 20/May/2026 13:09:00 | Reported IP: 91.239.78.146 mod_security | id: 930130 | UA/group.my_doma ...
show more
Date: 20/May/2026 13:09:00 | Reported IP: 91.239.78.146 mod_security | id: 930130 | UA/group.my_domain/- | Connections: 2 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /debug/default/view; /.env | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-20 06:29:12
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 02:29:04.905033 2026] [security2:error] [pid 21034:tid 21034] [client 91.239.78.146:47881] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gsrsv.org"] [uri "/.env.local"] [unique_id "ag1UsHIzlCkWhtdLxzIePwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-05-20 06:00:06
(2 weeks ago)
Date: 20/May/2026 08:53:00 | Reported IP: 91.239.78.146 mod_security | id: 930130 | UA/group.my_doma ...
show more
Date: 20/May/2026 08:53:00 | Reported IP: 91.239.78.146 mod_security | id: 930130 | UA/group.my_domain/- | Connections: 22 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /api/.env; /app/.env; /backend/.env; /config/.env; /core/.env; /.env.backup; /.env.bak; /.env.development; /.env.example; /.env.local; /.env.old; /.env.production; /.env.save; /.env.staging; /.git/config; /laravel/.env; /public/.env; /server/.env; /shared/.env; /src/.env; /.vercel/.env.production.local; /web/.env | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
Anonymous
2026-05-20 05:06:35
(2 weeks ago)
Blocked: Reason='Suspicious traffic score=80 (review-based detection)'; Requests=24
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-20 04:42:19
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 00:42:11.410937 2026] [security2:error] [pid 31114:tid 31114] [client 91.239.78.146:34017] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graymatterofdc.com"] [uri "/.env.development"] [unique_id "ag07o37AO0-JfQ5-FWMtpwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-20 04:14:23
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ง๐ท
P1n4
2026-05-20 04:11:19
(2 weeks ago)
Heimdal IDS auto-block: sensitive_file (score=0.90)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 03:39:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 91.239.78.146 (dedicated.vsys.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 23:39:39.623931 2026] [security2:error] [pid 23211:tid 23211] [client 91.239.78.146:45613] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gpahomeinspections.com"] [uri "/.env.save"] [unique_id "ag0s-wP28IIoaUYlTdQHYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
clamehost.it
2026-05-19 14:48:13
(2 weeks ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
Anonymous
2026-05-19 14:38:25
(2 weeks ago)
(caddyscan) Scanner path probe from 91.239.78.146 (UA/Ukraine/dedicated.vsys.host): 5 in the last 36 ...
show more
(caddyscan) Scanner path probe from 91.239.78.146 (UA/Ukraine/dedicated.vsys.host): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 91.239.78.146 - - [19/May/2026:14:38:08 +0000] "GET /.env.staging HTTP/1.1"
[REDACTED] 200 2627 91.239.78.146 - - [19/May/2026:14:38:10 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 91.239.78.146 - - [19/May/2026:14:38:13 +0000] "GET /.env.bak HTTP/1.1"
[REDACTED] 200 2627 91.239.78.146 - - [19/May/2026:14:38:15 +0000] "GET /.env.old HTTP/1.1"
[REDACTED] 200 2627 91.239.78.146 - - [19/May/2026:14:38:20 +0000] "GET /.env.example HTTP/1.1"
show less
Port Scan
๐ฑ๐ป
garmtech.com
2026-05-19 11:09:25
(2 weeks ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack