๐บ๐ธ
mnsf
2026-09-19 00:05:07
(11 minutes ago)
Abuse Detected (44)
Brute-Force
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-09-19 00:04:53
(12 minutes ago)
bad bot
Bad Web Bot
๐บ๐ธ
lavnet.net
2026-09-18 23:59:54
(17 minutes ago)
45.138.12.40 - - [18/Sep/2026:23:59:50 +0000] "GET /..%ef%bc%8f..%ef%bc%8f.env?_=15xhqv1j&v=ax664 HT ...
show more
45.138.12.40 - - [18/Sep/2026:23:59:50 +0000] "GET /..%ef%bc%8f..%ef%bc%8f.env?_=15xhqv1j&v=ax664 HTTP/1.1" 404 2066 "https://www.google.com/" "Mozilla/5.0 (Linux; Android 14; SM-S918B Build/UP1A.231005.007) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/25.0 Chrome/121.0.0.0 Mobile Safari/537.36"
45.138.12.40 - - [18/Sep/2026:23:59:51 +0000] "GET /..%ef%bc%8f..%ef%bc%8fvar/www/html/.env?_=x45xg3ki&v=jqvmy HTTP/1.1" 404 2083 "https://t.co/vzw5zb2bqx" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
45.138.12.40 - - [18/Sep/2026:23:59:51 +0000] "GET /..%ef%bc%8f..%ef%bc%8fvar/www/.env?_=5ordchik&v=ye3rw HTTP/1.1" 404 2028 "https://www.bing.com/search?q=4t8yhc" "Mozilla/5.0 (Linux; U; Android 14; en-US; Redmi Note 13 Pro Build/UP1A.231005.007) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 UCBrowser/13.4.0.1306 Mobile Safari/537.36"
45.138.12.40 - - [18/Sep/2026:23:59:51 +0000] "GET /..%ef%bc%8f..%ef%bc%8fvar/www/html/wp-config.php?_=mmtxect0&
...
show less
Brute-Force
๐ฌ๐ง
consul.to
2026-09-18 23:59:47
(17 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-18 23:56:37
(20 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:55:14
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:55:11.132803 2026] [security2:error] [pid 17395:tid 17419] [client 45.138.12.40:52724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetooheys.com"] [uri "/.env.local"] [unique_id "aq3PX_boj3CEtM_EIDfOBAAAARQ"], referer: https://t.co/dga94poenk
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-09-18 23:51:34
(25 minutes ago)
Restricted File Access Attempt. Matched phrase "/.env" at REQUEST_FILENAME. (930130-147)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:35:47
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:35:40.627290 2026] [security2:error] [pid 3416:tid 3416] [client 45.138.12.40:35552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thereddoorlounge.com"] [uri "/.env"] [unique_id "aq3KzCb9FHOTNThwllnMrAAAAAw"], referer: https://www.bing.com/search?q=2i03e0
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-18 23:29:41
(47 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
IndigoRidge
2026-09-18 23:25:55
(50 minutes ago)
45.138.12.40 - - [18/Sep/2026:19:24:34 -0400] "GET /.env?_=n0ib1h6j&v=uudpi HTTP/1.1" 404 341 "https ...
show more
45.138.12.40 - - [18/Sep/2026:19:24:34 -0400] "GET /.env?_=n0ib1h6j&v=uudpi HTTP/1.1" 404 341 "https://www.facebook.com/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
45.138.12.40 - - [18/Sep/2026:19:25:47 -0400] "GET /%2e/.env?_=t146defo&v=0bo5n HTTP/1.1" 404 341 "https://www.google.com/search?q=qb2c4z" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
45.138.12.40 - - [18/Sep/2026:19:25:55 -0400] "GET /static/../.env?_=3kgqg2m6&v=1usg4 HTTP/1.1" 404 341 "https://duckduckgo.com/?q=nazms" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:17:06
(59 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:16:59.966117 2026] [security2:error] [pid 25082:tid 25082] [client 45.138.12.40:59518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenowhere-men.com"] [uri "/.env"] [unique_id "aq3Ga90fNKSMNe6LWCWMugAAAAo"], referer: https://www.facebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-18 23:00:21
(1 hour ago)
45.138.12.40 - - [18/Sep/2026:18:59:59 -0400] "GET /.env?_=6o8gdz45&v=2pibh HTTP/1.1" 403 5497 "http ...
show more
45.138.12.40 - - [18/Sep/2026:18:59:59 -0400] "GET /.env?_=6o8gdz45&v=2pibh HTTP/1.1" 403 5497 "https://twitter.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
45.138.12.40 - - [18/Sep/2026:19:00:07 -0400] "GET /.env?_=66ydvq0y&v=nopt7 HTTP/1.1" 403 5497 "https://www.bing.com/search?q=9nv6e6" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
45.138.12.40 - - [18/Sep/2026:19:00:21 -0400] "GET /.env?_=03dx6ote&v=cwef7 HTTP/1.1" 403 5497 "https://t.co/1wlo6s85ml" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 23:00:19
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 23:00:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 18:59:59.840984 2026] [security2:error] [pid 31307:tid 31307] [client 45.138.12.40:34394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thekingtones.com"] [uri "/.env"] [unique_id "aq3Cb1Jec9SEMe5uG3u98wAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack