๐ฌ๐ง
andypiper
2026-09-23 01:01:53
(5 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-23 00:13:05
(6 hours ago)
2026/09/23 01:13:02 [error] 325888#325888: *1425921 access forbidden by rule, client: 104.199.230.16 ...
show more
2026/09/23 01:13:02 [error] 325888#325888: *1425921 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /static//app/.env HTTP/2.0", host: "dolcevita.betatechnologies.info"
2026/09/23 01:13:03 [error] 325888#325888: *1425921 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /.//.env HTTP/2.0", host: "dolcevita.betatechnologies.info"
2026/09/23 01:13:03 [error] 325888#325888: *1425921 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /static//home/user/.env HTTP/2.0", host: "dolcevita.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ช๐ธ
scaballe
2026-09-23 00:10:35
(6 hours ago)
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 17:34:43
(12 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.199.230.164 - - [22/Sep/2026:19:34:43 +0200] "GET /.env.development HTTP/1.1" 403 485 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 17:31:45
(12 hours ago)
2026/09/22 18:31:43 [error] 325888#325888: *1366171 access forbidden by rule, client: 104.199.230.16 ...
show more
2026/09/22 18:31:43 [error] 325888#325888: *1366171 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /dashboard%2F.env HTTP/2.0", host: "web.betatechnologies.info"
2026/09/22 18:31:43 [error] 325888#325888: *1366146 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /_nuxt/../.env HTTP/2.0", host: "web.betatechnologies.info"
2026/09/22 18:31:44 [error] 325888#325888: *1366171 access forbidden by rule, client: 104.199.230.164, server: [redacted], request: "GET /api%2F.env HTTP/2.0", host: "web.betatechnologies.info"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-22 17:20:06
(13 hours ago)
| [Dangerous/Taiwan] Aggressive IP 104.199.230.164 (~30 hits). Type: DoS Defender- Web server 400 er ...
show more
| [Dangerous/Taiwan] Aggressive IP 104.199.230.164 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 17:09:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:09:50.116418 2026] [security2:error] [pid 7659:tid 7659] [client 104.199.230.164:45048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.solarfarms.info"] [uri "/static/../../../a/../../../../.env"] [unique_id "arK2XgNH_vapiQezoUb0ggAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:45:40
(13 hours ago)
[Tue Sep 22 18:45:37.507858 2026] [access_compat:error] [pid 3422621:tid 3422621] [client 104.199.23 ...
show more
[Tue Sep 22 18:45:37.507858 2026] [access_compat:error] [pid 3422621:tid 3422621] [client 104.199.230.164:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/rclone.conf
[Tue Sep 22 18:45:37.811015 2026] [access_compat:error] [pid 3421370:tid 3421370] [client 104.199.230.164:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws
[Tue Sep 22 18:45:37.869548 2026] [access_compat:error] [pid 3420515:tid 3420515] [client 104.199.230.164:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.aws
[Tue Sep 22 18:45:39.323659 2026] [access_compat:error] [pid 3420466:tid 3420466] [client 104.199.230.164:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.npmrc
[Tue Sep 22 18:45:39.548313 2026] [access_compat:error] [pid 3420493:tid 3420493] [client 104.199.230.164:0] AH01797: client denied by server configuration: /var/www/wordpress/loretlargent.info/.
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:40:48
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:40:43.874832 2026] [security2:error] [pid 26129:tid 26129] [client 104.199.230.164:43898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.keystroke.info"] [uri "/.env.backup"] [unique_id "arKvi2C0yEfGJIz-LIY1hQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-22 15:47:07
(14 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 15:46:14
(14 hours ago)
[22/Sep/2026:17:46:13 +0200] 179009197326.308675 104.199.230.164 0 217.154.7.177 443
[22/Sep/2026:17 ...
show more
[22/Sep/2026:17:46:13 +0200] 179009197326.308675 104.199.230.164 0 217.154.7.177 443
[22/Sep/2026:17:46:13 +0200] 179009197381.600773 104.199.230.164 0 217.154.7.177 443
[22/Sep/2026:17:46:13 +0200] 17900919734.743317 104.199.230.164 0 217.154.7.177 443
[22/Sep/2026:17:46:14 +0200] 179009197421.130668 104.199.230.164 0 217.154.7.177 443
[22/Sep/2026:17:46:14 +0200] 17900919740.678125 104.199.230.164 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:51:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:51:04.976240 2026] [security2:error] [pid 17892:tid 17892] [client 104.199.230.164:40556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.belgiophar.info"] [uri "/static../.env"] [unique_id "arKHyLd2aAfF58PhSiTapwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:31:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:31:06.075914 2026] [security2:error] [pid 9096:tid 9096] [client 104.199.230.164:55068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.info"] [uri "/web.config"] [unique_id "arKDGgPgnH10Q-tLzPLAAgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-09-22 13:12:08
(17 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:06:39
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.230.164 (164.230.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:06:35.175625 2026] [security2:error] [pid 513852:tid 513852] [client 104.199.230.164:44080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cypraea.info"] [uri "/.env.production"] [unique_id "arJTK26b1WUurV3fvCimegAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack