๐ณ๐ฑ
Site.eu
2026-06-13 02:35:56
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
polarolouis
2026-06-12 09:56:51
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
iNetWorker
2026-06-12 09:51:30
(1 week ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
mc4bbs
2026-06-12 08:04:06
(1 week ago)
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: ...
show more
Automated Apache detection on Windows host. 5 suspicious HTTP requests within 300 seconds. Examples: GET /.env.example -> 404 UA=""; GET /.env -> 404 UA=""; GET /api/.env -> 404 UA=""; GET /.env.local -> 404 UA=""; GET /.env.production -> 404 UA=""
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-12 07:36:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:36:37.674558 2026] [security2:error] [pid 11073:tid 11073] [client 88.151.33.123:59824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wheelworks.my"] [uri "/.env.example"] [unique_id "aiu3BSMjRJ5WfPK_k-ztzgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 04:09:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:09:46.333951 2026] [security2:error] [pid 21539:tid 21539] [client 88.151.33.123:42884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whatcausesmentalillness.com"] [uri "/.env"] [unique_id "aiuGils4lWSJuuqXtkaVJwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
enjoyably
2026-06-12 02:26:45
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
Anonymous
2026-06-12 02:08:31
(1 week ago)
Portscan: TCP/80 (6x), TCP/443 (4x)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-12 00:26:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 20:26:07.111757 2026] [security2:error] [pid 20499:tid 20499] [client 88.151.33.123:51006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weyoungreno.weyoungrenovations.com"] [uri "/.env"] [unique_id "aitSH-ncZyx7ZRZCtYDSSAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-06-11 23:30:55
(1 week ago)
Web attack. 88.151.33.123 - - [12/Jun/2026:01:30:55 +0200] "GET /api/.env HTTP/2.0" 444 0 "http://mk ...
show more
Web attack. 88.151.33.123 - - [12/Jun/2026:01:30:55 +0200] "GET /api/.env HTTP/2.0" 444 0 "http://mk.cx/api/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot"
88.151.33.123 - - [12/Jun/2026:01:30:55 +0200] "GET /.env.example HTTP/2.0" 404 742 "http://mk.cx/.env.example" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 22:17:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 18:17:24.495992 2026] [security2:error] [pid 18119:tid 18119] [client 88.151.33.123:38464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webserviceswest.com"] [uri "/.env.example"] [unique_id "aisz9PmkExYEiOqNZE1E2QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-11 21:59:51
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-11
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-06-11 21:30:54
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-06-11 19:46:25
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 88.151.33.123 (-): N in the last X secs
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 18:25:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 88.151.33.123 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 14:25:45.131983 2026] [security2:error] [pid 1854:tid 1854] [client 88.151.33.123:37100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weroinc.com"] [uri "/.env.example"] [unique_id "air9qYN26KzAa5SqxvU62wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack