๐บ๐ธ
chronos
2026-10-07 01:34:47
(4 days ago)
[AUTORAVALT][[06/10/2026 - 22:34:46 -03:00 UTC]
Attack from [181.215.65.114] Action: BLocKed
DDoS A ...
show more
[AUTORAVALT][[06/10/2026 - 22:34:46 -03:00 UTC]
Attack from [181.215.65.114] Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web App Attack -> Attempts to probe for or exploit insta]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
chronos
2026-10-07 00:55:36
(4 days ago)
[AUTORAVALT][[06/10/2026 - 21:55:35 -03:00 UTC]
Attack from [Private Customer]
[181.215.65.114]-[RAN ...
show more
[AUTORAVALT][[06/10/2026 - 21:55:35 -03:00 UTC]
Attack from [Private Customer]
[181.215.65.114]-[RANGE:181.215.65.0 - 181.215.65.255]
Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:12:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:12:30.865073 2026] [security2:error] [pid 1042:tid 1042] [client 181.215.65.114:50517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.94"] [uri "/crm/.env"] [unique_id "asVWLkTT8-UQ-WYk8oJPbgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:08:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:08:11.723736 2026] [security2:error] [pid 4055:tid 4055] [client 181.215.65.114:50351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.176"] [uri "/audio/.env"] [unique_id "asTWm4fFVSAYe6XtbR7-ogAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRNP
2026-10-06 06:41:23
(5 days ago)
_:80 181.215.65.114 - - [06/Oct/2026:06:41:22 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 ( ...
show more
_:80 181.215.65.114 - - [06/Oct/2026:06:41:22 +0000] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 05:33:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 01:33:34.077348 2026] [security2:error] [pid 1279878:tid 1279891] [client 181.215.65.114:54085] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.85"] [uri "/admin/.env"] [unique_id "asSILsUxoacKGcgo3oyqiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
geot
2026-10-06 01:31:26
(5 days ago)
GET /app/config/.env HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
chronos
2026-10-06 01:03:22
(5 days ago)
[AUTORAVALT][[05/10/2026 - 22:03:22 -03:00 UTC]
Attack from [181.215.65.114] Action: BLocKed
DDoS A ...
show more
[AUTORAVALT][[05/10/2026 - 22:03:22 -03:00 UTC]
Attack from [181.215.65.114] Action: BLocKed
DDoS Attack -> Participating in distributed denial-of-service.
Phishing -> Phishing websites and/or email.
Web Spam -> Comment/forum spam, HTTP referer spam, or other CMS spam.
Blog Spam -> CMS blog comment spam.
Web App Attack -> Attempts to probe for or exploit insta]
...
show less
DDoS Attack
Phishing
Web Spam
Blog Spam
Web App Attack
๐ช๐ธ
librebit
2026-10-05 19:53:18
(6 days ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 18:55:27
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 14:54:49.769912 2026] [security2:error] [pid 30918:tid 30918] [client 181.215.65.114:27167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.89"] [uri "/app/.env"] [unique_id "asPyeZ7CQZ1LOObpfz02cQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:46:24
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:45:55.465556 2026] [security2:error] [pid 22039:tid 22039] [client 181.215.65.114:38517] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.15"] [uri "/.env"] [unique_id "asO4IwJMljnWebJEj0mXCQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:04:15
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:03:46.830728 2026] [security2:error] [pid 14201:tid 14201] [client 181.215.65.114:32867] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.141"] [uri "/database/.env"] [unique_id "asOuQiguxBRqqnjvOH9KtgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 12:34:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 08:33:56.257104 2026] [security2:error] [pid 29827:tid 29827] [client 181.215.65.114:32851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.188"] [uri "/.env"] [unique_id "asOZNPIg7kJPVP44FBn_tgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XYCoderXY
2026-10-05 12:31:21
(6 days ago)
HTTP vulnerability probe: 1 request at 2026-10-05 12:31:21 UTC. Targets: exposed secrets, config and ...
show more
HTTP vulnerability probe: 1 request at 2026-10-05 12:31:21 UTC. Targets: exposed secrets, config and source-control files. Examples: /public/.env. No legitimate visitor of this server sends these requests. Source blocked. - Lumerux Defense (lumerux.com), automated report. Contact: [email protected]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 11:28:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 181.215.65.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 07:27:57.917820 2026] [security2:error] [pid 22845:tid 22845] [client 181.215.65.114:51969] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.153"] [uri "/laravel/.env"] [unique_id "asOJvVPo-_kx7QuqlPus0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack