Anonymous
2026-05-15 16:10:06
(4 months ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
Anonymous
2026-05-15 12:19:00
(4 months ago)
web hacking
Brute-Force
Web App Attack
Hacking
πΊπΈ
etu brutus
2026-05-15 07:57:05
(4 months ago)
206.189.200.233 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
π¨π
Sophie Nina
2026-05-15 06:10:01
(4 months ago)
Automatically blocked by server
Fraud Orders
Anonymous
2026-05-14 20:21:26
(4 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-05-14 13:05:32
(4 months ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-14 09:51:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 05:51:05.597119 2026] [security2:error] [pid 27504:tid 27504] [client 206.189.200.233:33822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soglove.com"] [uri "/.env_backup"] [unique_id "agWbCT5v3MP1gP8MaluDfQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-05-14 09:32:51
(4 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-05-14 05:33:51
(4 months ago)
101 requests with url.path *.env
Brute-Force
Bad Web Bot
Anonymous
2026-05-14 04:26:09
(4 months ago)
(caddyscan) Scanner path probe from 206.189.200.233 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(caddyscan) Scanner path probe from 206.189.200.233 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 206.189.200.233 - - [14/May/2026:04:26:03 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 206.189.200.233 - - [14/May/2026:04:26:05 +0000] "GET /.env.swp HTTP/1.1"
[REDACTED] 200 2627 206.189.200.233 - - [14/May/2026:04:26:05 +0000] "GET /.env.backup HTTP/1.1"
[REDACTED] 200 2627 206.189.200.233 - - [14/May/2026:04:26:05 +0000] "GET /.env.bak HTTP/1.1"
[REDACTED] 200 2627 206.189.200.233 - - [14/May/2026:04:26:05 +0000] "GET /.env.dev HTTP/1.1"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-05-14 01:18:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 21:18:10.708577 2026] [security2:error] [pid 26327:tid 26327] [client 206.189.200.233:34830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smsindustries.com"] [uri "/backend/.env"] [unique_id "agUi0vJG9Q5B5R1R8zlzlAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-05-14 01:16:12
(4 months ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
Anonymous
2026-05-14 00:59:02
(4 months ago)
Bot / scanning and/or hacking attempts: GET /backend/.env HTTP/1.1, GET /.env_backup HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /backend/.env HTTP/1.1, GET /.env_backup HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.sample HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env_secret HTTP/1.1, GET /admin/.env HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-14 00:46:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 20:46:29.512639 2026] [security2:error] [pid 9441:tid 9441] [client 206.189.200.233:33812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smoothiessoupssalads.com"] [uri "/config/.env"] [unique_id "agUbZRjq7s_E-qzLgLNp9gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-13 23:18:27
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 206.189.200.233 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 19:18:20.108681 2026] [security2:error] [pid 8267:tid 8267] [client 206.189.200.233:44832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smilingorc.com"] [uri "/admin/.env"] [unique_id "agUGvDWoMqEFX3RyQNLQRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack