๐บ๐ธ
MatCat
2026-07-18 09:34:54
(2 days ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐จ๐ญ
TheCoon
2026-07-17 13:30:01
(2 days ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 11:06:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:06:47.742193 2026] [security2:error] [pid 3921969:tid 3921969] [client 140.246.133.247:56047] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ronelgas.com"] [uri "/backend/.env"] [unique_id "aloMx7vhLM27-BYmsc5ongAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 07:33:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:33:45.149649 2026] [security2:error] [pid 2365:tid 2365] [client 140.246.133.247:42041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "godcanuseyou.com"] [uri "/.env.old"] [unique_id "alna2aK9Wo991tsguY-RUgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 06:47:44
(3 days ago)
(caddyscan) Scanner path probe from 140.246.133.247 (CN/China/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 140.246.133.247 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 140.246.133.247 - - [17/Jul/2026:06:47:37 +0000] "GET /actuator/env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [17/Jul/2026:06:47:38 +0000] "GET /actuator/configprops HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [17/Jul/2026:06:47:41 +0000] "GET /backup/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [17/Jul/2026:06:47:42 +0000] "GET /backups/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [17/Jul/2026:06:47:43 +0000] "GET /old/.env HTTP/1.1"
show less
Port Scan
๐ต๐ฑ
lns.bz
2026-07-17 05:28:47
(3 days ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 03:53:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:53:51.796301 2026] [security2:error] [pid 225914:tid 225914] [client 140.246.133.247:58823] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oshawinfree.robtown.com"] [uri "/.env~"] [unique_id "almnTzZFXmMj3_vQN1_c6QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 03:09:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:09:02.639407 2026] [security2:error] [pid 136678:tid 136678] [client 140.246.133.247:52736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "easyweb-publishing.com"] [uri "/.env.sample"] [unique_id "almczo8kU9Hk7q7CYLY_yQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-07-17 02:01:44
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-16 22:28:42
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
todix
2026-07-16 21:34:10
(3 days ago)
WebAttack or semilar from 140.246.133.247
Web App Attack
Anonymous
2026-07-16 20:26:39
(3 days ago)
(caddyscan) Scanner path probe from 140.246.133.247 (CN/China/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 140.246.133.247 (CN/China/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 140.246.133.247 - - [16/Jul/2026:20:26:36 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [16/Jul/2026:20:26:37 +0000] "GET /src/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [16/Jul/2026:20:26:37 +0000] "GET /config/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [16/Jul/2026:20:26:37 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 140.246.133.247 - - [16/Jul/2026:20:26:38 +0000] "GET /frontend/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-16 19:57:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 15:57:05.881687 2026] [security2:error] [pid 25734:tid 25734] [client 140.246.133.247:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.c2cservices.com"] [uri "/.env"] [unique_id "alk3kZat2BiRvxw5eHDZJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
GuangChen233
2026-07-16 19:17:34
(3 days ago)
Blocked by CrowdSec: Ip 140.246.133.247 performed 'crowdsecurity/http-sensitive-files' (6 events ove ...
show more
Blocked by CrowdSec: Ip 140.246.133.247 performed 'crowdsecurity/http-sensitive-files' (6 events over 7.008253047s) at 2026-07-16 19:17:32.744172162 0000 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 18:22:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 140.246.133.247 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 14:22:01.355586 2026] [security2:error] [pid 21142:tid 21142] [client 140.246.133.247:34501] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texaspropertyinspection.com"] [uri "/app/.env"] [unique_id "alkhSSwueL0H4PaPaT-rTgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack