๐ฉ๐ช
TheDjRider
2026-09-16 01:17:00
(6 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-16T01:16:55.22097617Z. Context: http_status=404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:42:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:42:20.076371 2026] [security2:error] [pid 4608:tid 4608] [client 108.181.155.226:59079] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.190"] [uri "/.env"] [unique_id "aqnl7Cy7GQilVctUIIdnZAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-16 00:27:19
(6 days ago)
Accessed trap at '/.env'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:12:29
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:12:25.670802 2026] [security2:error] [pid 8447:tid 8447] [client 108.181.155.226:63969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.109"] [uri "/.env"] [unique_id "aqne6bzOvAoUjAa0D25ZggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 23:39:39
(6 days ago)
108.181.155.226 - - [15/Sep/2026:20:39:37 -0300] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; ...
show more
108.181.155.226 - - [15/Sep/2026:20:39:37 -0300] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
108.181.155.226 - - [15/Sep/2026:20:39:38 -0300] "GET /.env HTTP/1.1" 403 180 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Port Scan
๐ฎ๐ณ
Starburst SysOp Team
2026-09-15 22:47:15
(6 days ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-bom2-2)
Hacking
Bad Web Bot
๐ฉ๐ช
iNetWorker
2026-09-15 22:46:01
(6 days ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:10:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:09:57.054313 2026] [security2:error] [pid 16063:tid 16063] [client 108.181.155.226:56104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.72"] [uri "/.env"] [unique_id "aqnCNdRm64dAzBecAgUCJgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:14:02
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:13:55.389225 2026] [security2:error] [pid 29256:tid 29256] [client 108.181.155.226:60004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.27"] [uri "/.env"] [unique_id "aqm1E-JtvPmYqAV-84-uqgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:47:00
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:46:56.724491 2026] [security2:error] [pid 22519:tid 22519] [client 108.181.155.226:56210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.27"] [uri "/.env"] [unique_id "aqmSoCzyLI1TtKeKn0RKrgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:49:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:49:21.544975 2026] [security2:error] [pid 12861:tid 12861] [client 108.181.155.226:65505] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.161"] [uri "/.env"] [unique_id "aql3EfHgacfh9WSNox_0cAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 15:21:21
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 11:21:15.807612 2026] [security2:error] [pid 759:tid 899] [client 108.181.155.226:64113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.44"] [uri "/.env"] [unique_id "aqlia5_4cRd5IdJfy2WwQAAAApM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 15:06:18
(6 days ago)
[ti-hoogstraov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Exampl ...
show more
[ti-hoogstraov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 108.181.155.226 - - \[15/Sep/2026:10:44:31 +0200\] "GET /.env HTTP/1.1" 404 7405 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-09-15 13:53:04
(6 days ago)
blocked for webapp attack | path requested: /.env | seen at 2026-09-15 13:52:37.385 |
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 13:37:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 108.181.155.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:37:19.409341 2026] [security2:error] [pid 19308:tid 19308] [client 108.181.155.226:51371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.226"] [uri "/.env"] [unique_id "aqlKD7MQconu3F-82RI5DwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack