๐ซ๐ท
pm33
2026-09-27 22:24:08
(4 hours ago)
Unsolicited connection attempts or aggressive port scan.
Port Scan
๐ซ๐ท
Vaction
2026-09-27 17:46:31
(8 hours ago)
45.8.19.221 - - [27/Sep/2026:19:46:30 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows ...
show more
45.8.19.221 - - [27/Sep/2026:19:46:30 +0200] "GET /.env HTTP/1.1" 404 437 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
show less
Hacking
Bad Web Bot
Web App Attack
๐ง๐ท
Host One
2026-09-27 16:50:08
(9 hours ago)
T-Pot Honeypot alert: 11 malicious events (exploit_attempt, port_scan) detected.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-27 16:37:25
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:37:19.882440 2026] [security2:error] [pid 13292:tid 13319] [client 45.8.19.221:60777] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.125"] [uri "/library/.env"] [unique_id "arlGPxlx6E5Fw2KjgGnF4AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HoneyPotFRI
2026-09-27 12:05:40
(14 hours ago)
45.8.19.221 - - [27/Sep/2026:14:05:27 +0200] "GET /base/.env HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Win ...
show more
45.8.19.221 - - [27/Sep/2026:14:05:27 +0200] "GET /base/.env HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36"
45.8.19.221
...
show less
Bad Web Bot
Web App Attack
๐ท๐ธ
Smel
2026-09-27 07:07:43
(19 hours ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 05:52:35
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 01:52:04.539919 2026] [security2:error] [pid 12259:tid 12259] [client 45.8.19.221:40323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.65"] [uri "/crm/.env"] [unique_id "arivBNx6AEmgqkPtPe6akAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 05:25:16
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 01:25:06.860294 2026] [security2:error] [pid 2982:tid 2982] [client 45.8.19.221:43507] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.193"] [uri "/database/.env"] [unique_id "ariosgs2QITw-FpOWHrpmQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-27 00:45:20
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.8.19.221 (US/United States/-): 1 in t ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 45.8.19.221 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.8.19.221 - - [27/Sep/2026:02:45:18 +0200] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 200 12000 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.36" "-" host=51.89.2.96
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-27 00:17:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:17:23.757179 2026] [security2:error] [pid 8009:tid 8009] [client 45.8.19.221:62031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.9"] [uri "/app/.env"] [unique_id "arhgk3ttZTPBkJpqac271AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-26 19:47:23
(1 day ago)
Attempted access to sensitive endpoint (/.env) detected. Automated scan or unauthorized probing.
Web App Attack
๐ฉ๐ช
HoneyPot-FrPri
2026-09-26 12:35:50
(1 day ago)
45.8.19.221 - - 181.214.99.65 [26/Sep/2026:14:35:45 +0200] "GET /vendor/.env HTTP/1.1" 404 188 "-" " ...
show more
45.8.19.221 - - 181.214.99.65 [26/Sep/2026:14:35:45 +0200] "GET /vendor/.env HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.183 Safari/537.
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 12:08:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.8.19.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 08:08:34.282677 2026] [security2:error] [pid 14917:tid 14917] [client 45.8.19.221:60365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.19"] [uri "/crm/.env"] [unique_id "are1wgO6mr3EbodWfTmmUAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-09-12 14:21:00
(2 weeks ago)
IPBlock protected site ID [3390-wh].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-09-10 05:38:03
(2 weeks ago)
Wordfence waf block on registrymatters
Web App Attack