Anonymous
2026-09-17 12:29:31
(4 days ago)
172.69.214.8 - - [17/Sep/2026:14:29:26 +0200] "GET /site/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Wi ...
show more
172.69.214.8 - - [17/Sep/2026:14:29:26 +0200] "GET /site/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.69.214.8 - - [17/Sep/2026:14:29:26 +0200] "GET /public/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.69.214.8 - - [17/Sep/2026:14:29:26 +0200] "GET /admin/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.69.214.8 - - [17/Sep/2026:14:29:27 +0200] "GET /backend/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
172.69.214.8 - - [17/Sep/2026:14:29:28 +0200] "GET /server/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
17
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 10:39:32
(4 weeks ago)
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
172.69.214.8 - - [24/Aug/2026:12:39:31 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mawan
2026-08-22 18:33:31
(4 weeks ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ง๐ช
madeit
2026-08-12 21:37:00
(1 month ago)
Web App Attack
๐ฌ๐ง
OptimusGO
2026-06-22 02:44:23
(2 months ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-22 03:44:23 UTC
Log evidence:
06/22/2026-03:44:17.697290 [**] [1:1000103:1] SECURITY Management Port Probe - CRITICAL [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 172.69.214.8:12481 -> 185.127.18.66:8443
06/22/2026-03:44:19.816891 [**] [1:1000101:2] SECURITY Port Scan Detected - Multiple Unauthorized Ports [**] [Classification: Attempted Information Leak] [Priority: 1] {TCP} 172.69.214.8:12488 -> 185.127.18.66:8443
show less
Port Scan
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-06-13 22:04:55
(3 months ago)
Auto-ban: >3000 req/min op 2026-06-13
Web App Attack
SSH
Hacking
๐ฆ๐บ
oncord
2026-05-30 10:37:47
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-04-05 11:22:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 07:22:08.516671 2026] [security2:error] [pid 14543:tid 14543] [client 172.69.214.8:11907] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "301i.com"] [uri "/admin/.env"] [unique_id "adJF4LU1eCigyS5pwaPM_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 06:13:12
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 02:13:05.672790 2026] [security2:error] [pid 7999:tid 7999] [client 172.69.214.8:9852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.noscentpro.com"] [uri "/.env.example"] [unique_id "adH9cbEd0mnTfiaJKJqwnwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:21:37
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:21:30.161770 2026] [security2:error] [pid 798:tid 798] [client 172.69.214.8:9992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "country.ic1.biz"] [uri "/.git/refs/heads/main"] [unique_id "adGA2ty4c3y100rlzP8VRwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 14:49:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 10:49:26.145004 2026] [security2:error] [pid 21799:tid 21799] [client 172.69.214.8:11583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.astariamusic.com"] [uri "/web/.env"] [unique_id "adEk9lHU4atlEVSmf9lG-QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 13:37:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 09:37:49.393012 2026] [security2:error] [pid 13606:tid 13606] [client 172.69.214.8:11091] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ttlatl.dragoldio.com"] [uri "/.env.json"] [unique_id "adEULe6NrfIAZrbPI8mSqAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 12:57:47
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 08:57:40.767726 2026] [security2:error] [pid 15538:tid 15538] [client 172.69.214.8:14145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cayman-islands-real-estate.com"] [uri "/.env.php"] [unique_id "adEKxH4cNVWGayjefqw-QwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 07:38:53
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 03:38:45.844697 2026] [security2:error] [pid 27650:tid 27650] [client 172.69.214.8:9260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.allafricaadventures.com"] [uri "/.env.staging"] [unique_id "adDABX9yE6CEvJRC1zywxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 06:20:33
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.214.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 02:20:30.169730 2026] [security2:error] [pid 31516:tid 31516] [client 172.69.214.8:9692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.cms2020.com"] [uri "/.env.php"] [unique_id "adCtroFgEafuGlPqyDiGcQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack