๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 21:59:56
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-07.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
consul.to
2026-06-08 09:57:59
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-06-08 07:51:55
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
Little Iguana
2026-06-08 06:46:15
(2 weeks ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
Anonymous
2026-06-08 03:33:02
(2 weeks ago)
Bot / scanning and/or hacking attempts: GET /api/.env HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /dev ...
show more
Bot / scanning and/or hacking attempts: GET /api/.env HTTP/1.1, GET /laravel/.env HTTP/1.1, GET /dev/.env HTTP/1.1, GET /admin/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-06-08 02:35:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.164.64.9 (US/United States/-): 5 in the las ...
show more
(mod_security) mod_security (id:210492) triggered by 194.164.64.9 (US/United States/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-07 23:17:47
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
LRNP
2026-06-07 18:16:27
(2 weeks ago)
_:443 194.164.64.9 - - [07/Jun/2026:18:16:26 +0000] "GET /.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (M ...
show more
_:443 194.164.64.9 - - [07/Jun/2026:18:16:26 +0000] "GET /.env HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 13:06:05
(2 weeks ago)
(caddyscan) Scanner path probe from 194.164.64.9 (US/United States/-): 5 in the last 3600 secs; Port ...
show more
(caddyscan) Scanner path probe from 194.164.64.9 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 194.164.64.9 - - [07/Jun/2026:13:06:04 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 194.164.64.9 - - [07/Jun/2026:13:06:04 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 194.164.64.9 - - [07/Jun/2026:13:06:04 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 194.164.64.9 - - [07/Jun/2026:13:06:04 +0000] "GET /admin/.env HTTP/1.1"
[REDACTED] 200 2627 194.164.64.9 - - [07/Jun/2026:13:06:04 +0000] "GET /core/.env HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-07 12:40:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.164.64.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 194.164.64.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 08:40:38.386590 2026] [security2:error] [pid 31821:tid 31821] [client 194.164.64.9:46588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verenacastle.com"] [uri "/.env"] [unique_id "aiVmxqeQdR3Ou66TtYJz6gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 11:36:54
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 194.164.64.9 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:949110) triggered by 194.164.64.9 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 07:36:48.993398 2026] [security2:error] [pid 18823:tid 18823] [client 194.164.64.9:36234] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lawdude.org"] [uri "/api/.env"] [unique_id "aiVX0H9WvluZ027OQkJAIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-06-07 10:55:18
(2 weeks ago)
[07/Jun/2026:12:55:16.933040 +0200] aiVOFGka4tgyw4xvr3q8FgAAAII 194.164.64.9 48990 38.242.227.117 70 ...
show more
[07/Jun/2026:12:55:16.933040 +0200] aiVOFGka4tgyw4xvr3q8FgAAAII 194.164.64.9 48990 38.242.227.117 7081
[07/Jun/2026:12:55:16.966006 +0200] aiVOFNQcqrVe70iEzU4idQAAAA0 194.164.64.9 48994 38.242.227.117 7081
[07/Jun/2026:12:55:16.977737 +0200] aiVOFGka4tgyw4xvr3q8FwAAAIY 194.164.64.9 48992 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐จ๐ญ
4server
2026-06-07 10:50:10
(2 weeks ago)
[SunJun0712:50:03.9538142026][security2:error][pid2774108:tid2774320][client194.164.64.9:0]ModSecuri ...
show more
[SunJun0712:50:03.9538142026][security2:error][pid2774108:tid2774320][client194.164.64.9:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"privilege-service.ch\"][uri\"/member/.env\"][unique_id\"aiVM20F9d5R62Tq7Y4BTrwAAAI4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
Matthew Ping
2026-06-07 09:45:01
(2 weeks ago)
ModSecurity rule 949110 triggered on wp1. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐จ๐ฆ
polycoda
2026-06-07 08:59:05
(2 weeks ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack