๐ซ๐ท
Catalin Negru
2026-08-21 13:06:15
(1 month ago)
2026-08-10 05:47:13,452 fail2ban.actions [722]: NOTICE [laravel-env] Ban 149.88.104.19
2026- ...
show more
2026-08-10 05:47:13,452 fail2ban.actions [722]: NOTICE [laravel-env] Ban 149.88.104.19
2026-08-10 05:47:13,594 fail2ban.actions [722]: NOTICE [apache-404] Ban 149.88.104.19
2026-08-10 05:47:13,648 fail2ban.actions [722]: NOTICE [apache-security] Ban 149.88.104.19
2026-08-10 05:47:13,675 fail2ban.actions [722]: NOTICE [web-scanner] Ban 149.88.104.19
2026-08-10 05:47:13,683 fail2ban.actions [722]: NOTICE [apache-dirscan] Ban 149.88.104.19
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
geot
2026-08-11 12:08:19
(1 month ago)
POST / HTTP/1.1
GET /<<removed>>/.env HTTP/1.1
GET /.env HTTP/1.1
GET /admin/.env HTTP/1.1
GET /vend ...
show more
POST / HTTP/1.1
GET /<<removed>>/.env HTTP/1.1
GET /.env HTTP/1.1
GET /admin/.env HTTP/1.1
GET /vendor/.env HTTP/1.1
show less
Port Scan
Hacking
Web App Attack
Anonymous
2026-08-11 00:25:27
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-10 23:33:55
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 19:33:48.522329 2026] [security2:error] [pid 1101787:tid 1101792] [client 149.88.104.19:62396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.silvestricarpet.com"] [uri "/.env"] [unique_id "anpf3P0JfdU1bCh800VcKwAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 05:32:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 01:31:52.627741 2026] [security2:error] [pid 513643:tid 513643] [client 149.88.104.19:56673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oakleighfarm.com"] [uri "/.env"] [unique_id "anliSAsEEkf3n4m4SN7YtgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 05:02:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 01:02:43.139035 2026] [security2:error] [pid 2519042:tid 2519042] [client 149.88.104.19:50940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.solutiongroove.com"] [uri "/.env"] [unique_id "anlbcylcNAsM9KnQupKP4AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-10 02:49:59
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-10 02:47:20
(1 month ago)
2026-08-10 05:47:13,452 fail2ban.actions [722]: NOTICE [laravel-env] Ban 149.88.104.19
2026- ...
show more
2026-08-10 05:47:13,452 fail2ban.actions [722]: NOTICE [laravel-env] Ban 149.88.104.19
2026-08-10 05:47:13,594 fail2ban.actions [722]: NOTICE [apache-404] Ban 149.88.104.19
2026-08-10 05:47:13,648 fail2ban.actions [722]: NOTICE [apache-security] Ban 149.88.104.19
2026-08-10 05:47:13,675 fail2ban.actions [722]: NOTICE [web-scanner] Ban 149.88.104.19
2026-08-10 05:47:13,683 fail2ban.actions [722]: NOTICE [apache-dirscan] Ban 149.88.104.19
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-10 02:23:42
(1 month ago)
Requested credentials/secrets files (.env, cloud credential files, repository internals) - credentia ...
show more
Requested credentials/secrets files (.env, cloud credential files, repository internals) - credential harvesting scan | req: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 01:57:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com ...
show more
(mod_security) mod_security (id:210492) triggered by 149.88.104.19 (unn-149-88-104-19.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 21:57:17.617817 2026] [security2:error] [pid 1782157:tid 1782157] [client 149.88.104.19:56838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.aliciagrant.com"] [uri "/.env"] [unique_id "ankv_UtMlTJX6nSVVwuu2QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-10 00:59:36
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: 51.83.237.XX | URI: /.env | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-06-14 15:50:05
(3 months ago)
| Multiple SQL injection attempts from same source ip.(multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-03-19 19:34:38
(6 months ago)
Aggressive web scan
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-12-31 00:18:50
(8 months ago)
WP Login Scan Activities
Web App Attack
๐บ๐ธ
construct.net
2025-04-16 01:20:32
(1 year ago)
Triggered rate limiter
Bad Web Bot