Anonymous
2026-06-25 05:41:08
(1 hour ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ง๐ช
cmbplf
2026-06-25 05:32:13
(1 hour ago)
970 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-25 04:51:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3. ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 00:51:36.731595 2026] [security2:error] [pid 13528:tid 13528] [client 196.206.71.79:45306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apuntesdeinversion.com"] [uri "/.env"] [unique_id "ajyz2G0bkJRWN6_gm0rCXQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JustMeHere
2026-06-25 04:47:09
(2 hours ago)
[Thu Jun 25 00:47:03.762291 2026] [security2:error] [pid 251218:tid 251374] [client 196.206.71.79:33 ...
show more
[Thu Jun 25 00:47:03.762291 2026] [security2:error] [pid 251218:tid 251374] [client 196.206.71.79:33806] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "test2.yorknation.com"] [uri "/.env"] [unique_id "ajyyx3vXE0_4I1HS9yAP5wAAAJI"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 04:35:10
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3. ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 00:35:04.435129 2026] [security2:error] [pid 7220:tid 7339] [client 196.206.71.79:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindgardens.com"] [uri "/.env"] [unique_id "ajyv-H6kyT6qMDGZ1Lv0WwAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-25 04:30:26
(2 hours ago)
Probing for .env file:
196.206.71.79 - - [25/Jun/2026:06:30:19 +0200] "GET /.env HTTP/1.1" 403 146 " ...
show more
Probing for .env file:
196.206.71.79 - - [25/Jun/2026:06:30:19 +0200] "GET /.env HTTP/1.1" 403 146 "-" "-"
show less
Web App Attack
๐ซ๐ท
Baking333
2026-06-25 04:25:56
(2 hours ago)
[redacted] 196.206.71.79 - - [25/Jun/2026:05:25:54 +0100] "GET /.env HTTP/1.1" 302 6743 0/220142 "-" ...
show more
[redacted] 196.206.71.79 - - [25/Jun/2026:05:25:54 +0100] "GET /.env HTTP/1.1" 302 6743 0/220142 "-" "-" [redacted] 196.206.71.79 - - [25/Jun/2026:05:25:54 +0100] "GET / HTTP/1.1" 200 7646 0/88003 "https://[redacted]/.env" "-"
show less
Bad Web Bot
Web App Attack
๐ง๐ช
sid3windr
2026-06-25 04:07:08
(3 hours ago)
GET /.env (Tarpitted for 19m44s, wasted 69.49kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 04:05:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3. ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 00:05:11.034936 2026] [security2:error] [pid 20800:tid 20800] [client 196.206.71.79:58592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matomo.prolifeli.org"] [uri "/.env"] [unique_id "ajyo94SR2jXxeqz1unxAkQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 03:30:35
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3. ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 23:30:30.944110 2026] [security2:error] [pid 25272:tid 25272] [client 196.206.71.79:36984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eutoc.com"] [uri "/.env"] [unique_id "ajyg1mhmftC7M9lH538TBwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-25 02:46:23
(4 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-06-25 02:24:01
(4 hours ago)
Login credentials theft attempt
Hacking
๐ท๐บ
DZBOT
2026-06-25 02:18:03
(5 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-25 02:14:48
(5 hours ago)
(mod_security-custom) mod_security (id:210492) triggered by 196.206.71.79 (MA/Morocco/Rabat-Salรฉ-Kรฉn ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 196.206.71.79 (MA/Morocco/Rabat-Salรฉ-Kรฉnitra/Kenitra/adsl196-79-71-206-196.adsl196-3.iam.net.ma/[AS36903 MT-MPLS]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 02:08:52
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3. ...
show more
(mod_security) mod_security (id:210492) triggered by 196.206.71.79 (adsl196-79-71-206-196.adsl196-3.iam.net.ma): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:08:48.844165 2026] [security2:error] [pid 686:tid 686] [client 196.206.71.79:36834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cintiaparral.com"] [uri "/.env"] [unique_id "ajyNsM0z2pC0vjwokDoQ1AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack