Anonymous
2026-06-27 05:11:39
(49 minutes ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐ฌ๐ง
Yosi
2026-06-27 04:01:39
(1 hour ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
Lee Daniel
2026-06-27 02:16:06
(3 hours ago)
196.119.229.174 - - [26/Jun/2026:22:16:05 -0400] "GET /.env HTTP/1.1" 403 4804 "-" "Mozilla/5.0 (Mac ...
show more
196.119.229.174 - - [26/Jun/2026:22:16:05 -0400] "GET /.env HTTP/1.1" 403 4804 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:77.0) Gecko/20100101 Firefox/77.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-27 01:58:22
(4 hours ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐จ๐ญ
4server
2026-06-27 01:10:56
(4 hours ago)
[SatJun2703:10:53.4892222026][security2:error][pid2183281:tid2183357][client196.119.229.174:0]ModSec ...
show more
[SatJun2703:10:53.4892222026][security2:error][pid2183281:tid2183357][client196.119.229.174:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"kairoslab.ch\"][uri\"/.env\"][unique_id\"aj8jHes_el4ENOMBvc5DlAAAAMs\"]
show less
Hacking
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-26 21:45:52
(8 hours ago)
dot file probe
Web App Attack
๐ฎ๐ช
Jim Keir
2026-06-26 21:10:31
(8 hours ago)
2026-06-26 21:10:30 196.119.229.174 File scanning, blocking 196.119.229.174 for 5 minutes
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-06-26 16:31:59
(13 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 15:35:05
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 11:35:00.007215 2026] [security2:error] [pid 20451:tid 20451] [client 196.119.229.174:60999] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singleslidestrategy.com"] [uri "/.env"] [unique_id "aj6cJAHhz-MXOfRHRtLLgAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 13:34:51
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 09:34:46.246074 2026] [security2:error] [pid 26690:tid 26690] [client 196.119.229.174:61394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonathanwilson.me"] [uri "/.env"] [unique_id "aj5_9o4mkHIz9QQdqi48oQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-26 12:07:50
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-26 11:29:59
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 07:29:55.567988 2026] [security2:error] [pid 20054:tid 20054] [client 196.119.229.174:59315] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jessicabaer.com"] [uri "/.env"] [unique_id "aj5is7G_SAN7KPwOCO9RLQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-26 11:17:27
(18 hours ago)
Scanning for exploits - /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 10:32:19
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 196.119.229.174 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 06:32:13.565581 2026] [security2:error] [pid 10170:tid 10170] [client 196.119.229.174:63092] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "justinpenney.com"] [uri "/.env"] [unique_id "aj5VLWUzzoXTfq3vFrmcwAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-26 08:33:42
(21 hours ago)
330 requests with url.path *.env
Brute-Force
Bad Web Bot