Anonymous
2026-09-24 11:36:20
(1 day ago)
146.190.94.105 - - [24/Sep/2026:19:36:20 +0800] "GET /.env.production HTTP/1.1" 301 252 "-" "Mozilla ...
show more
146.190.94.105 - - [24/Sep/2026:19:36:20 +0800] "GET /.env.production HTTP/1.1" 301 252 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 01:28:16
(4 days ago)
146.190.94.105 - - [21/Sep/2026:09:28:16 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "Mozilla ...
show more
146.190.94.105 - - [21/Sep/2026:09:28:16 +0800] "GET /.env.production HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:137.0) Gecko/20100101 Firefox/137.0"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-09-20 23:37:15
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π³π±
Alt255
2026-09-20 16:25:08
(5 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 146.190.94.105 - - [20/Sep/2026:18:24:51 +0200] "GET /.env.dist HTTP/2.0" 403 69 "https://www.google.com/search?q=cleaningair.nl" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 05:52:32
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:52:24.271855 2026] [security2:error] [pid 2406041:tid 2406041] [client 146.190.94.105:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackhillsinfosec.org.mphq.net"] [uri "/.env.local"] [unique_id "aq90mBTEP_RzzDZLb_7YdwAAAAc"], referer: https://www.google.com/search?q=blackhillsinfosec.org.mphq.net
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-18 22:01:34
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-18 19:40:01
(1 week ago)
suspicious request in access.log
Web App Attack
π³π±
Alt255
2026-09-17 09:54:03
(1 week ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 146 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 146.190.94.105 - - \[17/Sep/2026:11:53:44 +0200\] "GET /.env.local HTTP/1.1" 404 44810 "https://cl-everevel-ynmoon.evelyn-tiger415.workers.dev/proxy\?modify\&proxyUrl=http%3A%2F%2Fhtr-nederland.nl%2F.env.local" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/135.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 16:10:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:10:34.042278 2026] [security2:error] [pid 5826:tid 5826] [client 146.190.94.105:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gilbert-consulting.com"] [uri "/.env"] [unique_id "aqlt-pKxVUYeqtq7ChmL0wAAAAI"], referer: https://www.google.com/search?q=gilbert-consulting.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
Telemetry2U.com
2026-09-10 09:04:38
(2 weeks ago)
Unauthorized connection attempt to port 8080
Hacking
π¨π
flaus
2026-09-10 00:31:47
(2 weeks ago)
$f2bV_matches
Hacking
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-09 16:07:23
(2 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-09 03:54:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:54:35.472564 2026] [security2:error] [pid 536260:tid 536282] [client 146.190.94.105:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emehache.net"] [uri "/.env"] [unique_id "aqDYe_YPKBkVkuFfreGTvgAAAA8"], referer: https://www.google.com/search?q=emehache.net
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-09 02:59:58
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.190.94.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:59:50.347397 2026] [security2:error] [pid 28608:tid 28608] [client 146.190.94.105:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crossfiregold.com"] [uri "/.git/config"] [unique_id "aqDLpoA5nIDGMKFsuOca6gAAAAk"], referer: https://www.google.com/search?q=crossfiregold.com
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-08 22:01:30
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking