πΉπ·
Detmach
2026-06-02 22:55:23
(1 day ago)
Security attack detected. Multiple failed attempts from 213.130.145.243. IP banned for 1440 minutes ...
show more
Security attack detected. Multiple failed attempts from 213.130.145.243. IP banned for 1440 minutes at 03.06.2026 01:55:15. Failed attempts: 1
show less
Brute-Force
Anonymous
2026-06-02 22:08:28
(1 day ago)
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:22:08:24 +0000] "GET /app/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:22:08:24 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:22:08:24 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:22:08:24 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:22:08:24 +0000] "GET /backend/.env HTTP/1.1"
show less
Port Scan
π§π·
Halux
2026-06-02 21:02:24
(1 day ago)
213.130.145.243 Probing protected path or service
Web App Attack
Anonymous
2026-06-02 17:34:44
(1 day ago)
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:17:34:39 +0000] "GET /core/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:17:34:39 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:17:34:39 +0000] "GET /member/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:17:34:39 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:17:34:39 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
π¦πΊ
2000cn.com.au
2026-06-02 13:36:43
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-06-02 12:06:35
(2 days ago)
Trying to access config files
Web App Attack
π«π·
dynamix
2026-06-02 11:05:41
(2 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-06-02 09:43:15
(2 days ago)
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 213.130.145.243 (FR/France/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:09:43:10 +0000] "GET /dev/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:09:43:10 +0000] "GET /new/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:09:43:10 +0000] "GET /backend/.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:09:43:10 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 213.130.145.243 - - [02/Jun/2026:09:43:10 +0000] "GET /api/.env HTTP/1.1"
show less
Port Scan
π¬π§
SilverZippo
2026-06-02 09:34:48
(2 days ago)
Web App Attack
Web App Attack
π«π·
masterguru
2026-06-02 09:28:03
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
πΊπΈ
Matthew Ping
2026-06-02 03:22:59
(2 days ago)
ModSecurity rule 949110 triggered on wp2. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
π¦πΊ
paulshipley.com.au
2026-06-02 00:41:29
(2 days ago)
[Tue Jun 02 10:41:28.261848 2026] [security2:error] [pid 181355] [client 213.130.145.243:41456] [cli ...
show more
[Tue Jun 02 10:41:28.261848 2026] [security2:error] [pid 181355] [client 213.130.145.243:41456] [client 213.130.145.243] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "whoson2day.com"] [uri "/app/.env"] [unique_id "ah4muAQLjFmI08Mdn7ZnNQAAAAY"]
...
show less
Web App Attack
Anonymous
2026-06-01 23:39:03
(2 days ago)
Bot / scanning and/or hacking attempts: GET /admin/.env HTTP/1.1, GET /dev/.env HTTP/1.1
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 18:49:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 14:48:59.162980 2026] [security2:error] [pid 1311:tid 1311] [client 213.130.145.243:56504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "csme-eprr.com"] [uri "/api/.env"] [unique_id "ah3UG2f1N2ZFG2F_Gj4mzAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-01 14:45:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 213.130.145.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 10:45:20.473052 2026] [security2:error] [pid 22639:tid 22639] [client 213.130.145.243:57804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adults-biz.com"] [uri "/.env"] [unique_id "ah2bABa9LjPKR6yQQClywwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack