π¦πΊ
CalmBrain
2026-07-18 16:01:22
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
MatCat
2026-07-18 09:34:55
(2 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
π«π·
dynamix
2026-07-17 13:38:02
(3 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 12:55:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:55:12.682869 2026] [security2:error] [pid 732985:tid 732985] [client 114.219.157.139:52957] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fluff2.instagenii.com"] [uri "/.env.production"] [unique_id "alomMCGGUKpFgV4UnEoTJgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 12:37:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 08:37:08.756295 2026] [security2:error] [pid 236836:tid 236836] [client 114.219.157.139:46771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kittencream.com.mykelmilur.com"] [uri "/.env.old"] [unique_id "aloh9MXf1-kyWTKK8pj6RwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 11:44:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:44:27.916766 2026] [security2:error] [pid 738341:tid 738341] [client 114.219.157.139:40869] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrsreclamation.com"] [uri "/.env.production.local"] [unique_id "aloVm2KMdbDDVJNju-rOvAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 08:49:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:49:03.993187 2026] [security2:error] [pid 27554:tid 27567] [client 114.219.157.139:36996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livetalkusa.com"] [uri "/.env.test"] [unique_id "alnsfzj7_y8RIp1zIqrJKQAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 08:23:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:23:37.103408 2026] [security2:error] [pid 667667:tid 667667] [client 114.219.157.139:51582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.springfieldtileexpert.worldchat.global"] [uri "/.env.staging"] [unique_id "alnmiSaZvnuUl0dmfjqgEAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 08:10:15
(3 days ago)
(caddyscan) Scanner path probe from 114.219.157.139 (CN/China/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 114.219.157.139 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 114.219.157.139 - - [17/Jul/2026:08:10:08 +0000] "GET /.env.dist HTTP/1.1"
[REDACTED] 200 2627 114.219.157.139 - - [17/Jul/2026:08:10:09 +0000] "GET /.env.template HTTP/1.1"
[REDACTED] 200 2627 114.219.157.139 - - [17/Jul/2026:08:10:10 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 114.219.157.139 - - [17/Jul/2026:08:10:12 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 114.219.157.139 - - [17/Jul/2026:08:10:13 +0000] "GET /.env.test.local HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-17 07:48:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:47:53.306641 2026] [security2:error] [pid 406804:tid 406804] [client 114.219.157.139:53899] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mangamaster.hongkonger.org"] [uri "/.env.example"] [unique_id "alneKW_sR70MBYZj6K24TwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
CalmBrain
2026-07-17 05:00:56
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-17 03:08:39
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:08:28.852536 2026] [security2:error] [pid 150750:tid 150750] [client 114.219.157.139:38673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easyweb-publishing.com"] [uri "/.env.backup"] [unique_id "almcrHUEEzHUDTStLtwqlgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
Olexiy Backend
2026-07-17 02:19:24
(3 days ago)
114.219.157.139
...
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-07-17 01:55:35
(3 days ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-17 01:45:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 114.219.157.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:44:55.991093 2026] [security2:error] [pid 22800:tid 22800] [client 114.219.157.139:44669] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cs4kids.org"] [uri "/.env.bak"] [unique_id "almJF4p57Hwf-k4SS7KEWQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack