๐ง๐ท
Halux
2026-06-19 00:03:58
(18 hours ago)
194.62.107.74 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 23:15:58
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 19:15:54.313429 2026] [security2:error] [pid 13941:tid 13941] [client 194.62.107.74:64887] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geckoturner.com"] [uri "/.env"] [unique_id "ajR8KkHQac2lzucWYn4qPAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 13:51:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 09:50:55.237446 2026] [security2:error] [pid 16784:tid 16806] [client 194.62.107.74:62127] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.idwic.com"] [uri "/.env"] [unique_id "ajP3v6i_-Wv5oe2DdQ4csgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 12:21:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 08:21:09.103878 2026] [security2:error] [pid 14146:tid 14146] [client 194.62.107.74:63927] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "countrysideinnkingston.com"] [uri "/.env"] [unique_id "ajPitXuVB0IZZ99EJ_WcHwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-18 10:36:36
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ง๐ท
Peregrine
2026-06-18 09:32:26
(1 day ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 194.62.107.74 172.68.35.106 - - [18/Jun/2026:06:32:20 -03 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 194.62.107.74 172.68.35.106 - - [18/Jun/2026:06:32:20 -0300] "GET /.env HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-18 09:30:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 05:30:06.456699 2026] [security2:error] [pid 4003:tid 4003] [client 194.62.107.74:29773] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abstractorangemusic.com"] [uri "/.env"] [unique_id "ajO6nlTaZhFjIXcwgaX2rgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 07:49:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 03:49:26.922807 2026] [security2:error] [pid 14867:tid 14867] [client 194.62.107.74:46063] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.prostar.industries"] [uri "/.env"] [unique_id "ajOjBiueFuFwfO1NbxXNtgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 07:27:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 03:27:27.002673 2026] [security2:error] [pid 315:tid 338] [client 194.62.107.74:29321] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aspencommission.com"] [uri "/.env"] [unique_id "ajOd351MlmlH_fOr9FpG-AAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 06:42:36
(1 day ago)
[Firewall Canary] Temporary ban due to firewall rule match [URI:*/.env]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 06:33:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 02:33:12.233784 2026] [security2:error] [pid 21757:tid 21757] [client 194.62.107.74:39195] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mhext.com"] [uri "/.env"] [unique_id "ajORKHvFy3WmIbet-cMlBgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 06:16:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 02:16:43.756260 2026] [security2:error] [pid 29190:tid 29190] [client 194.62.107.74:65533] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blockadegc.com"] [uri "/.env"] [unique_id "ajONS7JqEv7SQy2k7_iaqgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 05:51:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 194.62.107.74 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 01:51:43.530187 2026] [security2:error] [pid 7559:tid 7559] [client 194.62.107.74:29549] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frickandfracks.com"] [uri "/.env"] [unique_id "ajOHb5jDWpwHu0k427GghwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-17 22:07:18
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฑ๐ป
garmtech.com
2026-06-17 20:27:59
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack