Anonymous
2026-09-20 15:23:45
(2 days ago)
172.69.130.210 - - [20/Sep/2026:15:23:44 +0000] "GET /.env.stage HTTP/2.0" 404 198 "-" "Mozilla/5.0 ...
show more
172.69.130.210 - - [20/Sep/2026:15:23:44 +0000] "GET /.env.stage HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.186.198.52"
172.69.130.210 - - [20/Sep/2026:15:23:44 +0000] "GET /.env.docker HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.186.198.52"
172.69.130.210 - - [20/Sep/2026:15:23:45 +0000] "GET /.env.live HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.186.198.52"
172.69.130.210 - - [20/Sep/2026:15:23:45 +0000] "GET /.env.preprod HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "34.186.198.52"
172.69.130.210 - - [20/Sep/2026:15:23:45 +0000] "GET /.env.uat HTTP/2.0" 404 198 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Ap
...
show less
Port Scan
Brute-Force
๐ง๐ช
madeit
2026-09-14 14:31:55
(1 week ago)
Web App Attack
Anonymous
2026-09-01 22:14:35
(3 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ง๐ช
madeit
2026-08-16 23:52:55
(1 month ago)
Web App Attack
๐ฉ๐ช
paissangroup
2026-07-27 02:30:00
(1 month ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-06-11 05:05:56
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:33
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐บ๐ธ
MPL
2026-05-26 04:01:22
(3 months ago)
tcp/443 (5 or more attempts)
Port Scan
๐บ๐ธ
Watto
2026-05-17 15:47:58
(4 months ago)
Honeypot caught web brute force / scanning from LAN; 14 events recorded by kiosk-watchtower (Cowrie ...
show more
Honeypot caught web brute force / scanning from LAN; 14 events recorded by kiosk-watchtower (Cowrie + canary stack). Automated report from honeypot, please do not contact owner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Watto
2026-05-10 15:46:36
(4 months ago)
Honeypot caught web brute force / scanning from LAN; 14 events recorded by kiosk-watchtower (Cowrie ...
show more
Honeypot caught web brute force / scanning from LAN; 14 events recorded by kiosk-watchtower (Cowrie + canary stack). Automated report from honeypot, please do not contact owner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 07:41:09
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 03:41:01.723778 2026] [security2:error] [pid 1980536:tid 1980536] [client 172.69.130.210:10360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whatcausesmentalillness.com"] [uri "/.env.dev.local"] [unique_id "adYGjZ8Lgt2GGNzF-G8B2gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 20:53:29
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 16:53:25.638035 2026] [security2:error] [pid 1827045:tid 1827045] [client 172.69.130.210:12064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "embeddedtrade.com"] [uri "/.env.tmp"] [unique_id "adVuxd6Ubvd8ci07wVmjDAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 16:00:07
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 11:59:56.690126 2026] [security2:error] [pid 2240167:tid 2240167] [client 172.69.130.210:9805] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.borzois.com"] [uri "/.env.dev"] [unique_id "adUp_HnQpE6JCi-YcO6gigAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 15:21:49
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 11:21:44.625455 2026] [security2:error] [pid 1662059:tid 1662059] [client 172.69.130.210:12014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.guitarwisdom.com"] [uri "/.env_backup"] [unique_id "adUhCLSi2HaX6_bjqO-dTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 14:11:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.130.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 10:11:41.489325 2026] [security2:error] [pid 278975:tid 278975] [client 172.69.130.210:11198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carminestogo.buffaloweddingdeejay.com"] [uri "/.envrc"] [unique_id "adO_HYi1tXIsksFCg_9W_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack