Anonymous
2026-05-19 14:59:09
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.136.238 - - [19/May/2026:14:48:04 +0000] "HEAD /.git/config HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [19/May/2026:14:49:08 +0000] "GET /.git/objects/ HTTP/1.1"
[REDACTED] 200 0 149.143.136.238 - - [19/May/2026:14:53:22 +0000] "HEAD /.git/config HTTP/1.1"
[REDACTED] 200 0 149.143.136.238 - - [19/May/2026:14:59:05 +0000] "HEAD /root/.aws/config HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [19/May/2026:14:59:06 +0000] "GET /.env.dist HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-17 13:04:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 09:04:02.664687 2026] [security2:error] [pid 14445:tid 14445] [client 149.143.136.238:42487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schoolsliaisoncommunity.net"] [uri "/.env.live"] [unique_id "agm8wlQR12GdbXYQb3bDbAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 08:32:40
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 04:32:00.072146 2026] [security2:error] [pid 31824:tid 31824] [client 149.143.136.238:54701] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dbrooketaylor.com"] [uri "/api/.env"] [unique_id "agbaAKAwTHVM5cY7WOrKzwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 06:20:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 02:18:57.960968 2026] [security2:error] [pid 25305:tid 25305] [client 149.143.136.238:34405] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blanchebb.com"] [uri "/.env.stage"] [unique_id "aga60V1jlZtRC4pLj1PlvgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-14 15:44:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 11:44:26.415104 2026] [security2:error] [pid 5963:tid 5967] [client 149.143.136.238:42619] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "promo.heworeblack.com"] [uri "/.env.preview"] [unique_id "agXt2n1QtUurm98WK_idqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-10 16:36:57
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.136.238 - - [10/May/2026:16:36:53 +0000] "HEAD /wp-config.php.bak HTTP/1.1"
[REDACTED] 200 0 149.143.136.238 - - [10/May/2026:16:36:53 +0000] "HEAD /api/.env HTTP/1.1"
[REDACTED] 200 0 149.143.136.238 - - [10/May/2026:16:36:53 +0000] "HEAD /.env.local HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:36:53 +0000] "GET /api/actuator/configprops HTTP/1.1"
[REDACTED] 200 0 149.143.136.238 - - [10/May/2026:16:36:53 +0000] "HEAD /backend/.env HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-10 16:09:26
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:03:20 +0000] "GET /api/actuator/env HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:09:19 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:09:19 +0000] "GET /admin/.DS_Store HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:09:21 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [10/May/2026:16:09:21 +0000] "GET /.env.ini HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-09 11:26:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 07:26:35.914288 2026] [security2:error] [pid 28083:tid 28083] [client 149.143.136.238:48425] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.albertmassaad.com.easternimport.com"] [uri "/.git/config"] [unique_id "af8Z69zNFoxuekE4VfmQ4wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 10:02:54
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 0 149.143.136.238 - - [09/May/2026:10:02:50 +0000] "HEAD /root/.aws/credentials HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:10:02:50 +0000] "GET /.env.staging.local HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:10:02:50 +0000] "GET /.env.prod HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:10:02:51 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:10:02:52 +0000] "GET /.env.release HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 06:45:15
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:06:14:39 +0000] "GET /.env.staging.local HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:06:45:01 +0000] "GET /.git/objects/ HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:06:45:01 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:06:45:02 +0000] "GET /.env.docker HTTP/1.1"
[REDACTED] 200 2627 149.143.136.238 - - [09/May/2026:06:45:12 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-09 01:35:44
(4 months ago)
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 149.143.136.238 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: mlwildcardprobe-1777273352273162956.mlkjidgfedcbimayz8765876103218ee1-d870-48a9-ac27-a7908a88c817.bicities.org 200 0 149.143.136.238 - - [09/May/2026:00:55:11 +0000] "HEAD /.git/config HTTP/1.1"
mlwildcardprobe-1777273352273162956.mlkjidgfedcbimayz8765876103218ee1-d870-48a9-ac27-a7908a88c817.bicities.org 200 2627 149.143.136.238 - - [09/May/2026:00:55:31 +0000] "GET /.env.20231201 HTTP/1.1"
326042wildcardprobe-1777099243063312213.bicities.org 200 0 149.143.136.238 - - [09/May/2026:00:58:56 +0000] "HEAD /root/.aws/credentials HTTP/1.1"
4326042wildcardprobe-1777103739161464078.bicities.org 200 2627 149.143.136.238 - - [09/May/2026:01:35:40 +0000] "GET /api/actuator/heapdump HTTP/1.1"
4326042wildcardprobe-1777103739161464078.bicities.org 200 0 149.143.136.238 - - [09/May/2026:01:35:40 +0000] "HEAD /.aws/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
Charlesiv
2026-05-08 04:00:37
(4 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 7029 (Windstream Communications LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /env.development
Timestamp: 2026-05-08T02:56:14Z
Ray ID: 9f8530ac8936d705
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฌ๐ง
Apache
2026-05-07 08:15:16
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (US/United States/-): 5 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 149.143.136.238 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-05-07 00:16:10
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mnsf
2026-05-06 15:05:51
(4 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack