Anonymous
2026-09-19 01:38:00
(3 hours ago)
Host [89.140.181.213] was blocked via [DSM].
Brute-Force
π³π±
homeshowdomain.nl
2026-09-18 22:01:27
(6 hours ago)
Auto-ban: >3000 req/min op 2026-09-18
Web App Attack
SSH
Hacking
πΊπΈ
chronos
2026-09-18 11:54:20
(16 hours ago)
[AUTORAVALT][[18/09/2026 - 08:54:20 -03:00 UTC]
Attack from [89.140.181.213][89.140.181.213.static.u ...
show more
[AUTORAVALT][[18/09/2026 - 08:54:20 -03:00 UTC]
Attack from [89.140.181.213][89.140.181.213.static.user.ono.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, forum software, phpMyAdmin and various o]
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 11:47:43
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:47:39.217522 2026] [security2:error] [pid 29857:tid 29857] [client 89.140.181.213:49258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "go-901.com"] [uri "/.env"] [unique_id "aq0k2z61VW0woorZMdVwJwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 09:11:04
(19 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 08:57:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:57:19.347561 2026] [security2:error] [pid 18108:tid 18108] [client 89.140.181.213:58680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forinashgallery.com"] [uri "/.env"] [unique_id "aqz87zIIyIZLhwVxrdcuRAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 08:04:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 04:04:06.982533 2026] [security2:error] [pid 7462:tid 7462] [client 89.140.181.213:34542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixmywellwater.com"] [uri "/.env"] [unique_id "aqzwdhYKwevZ5zRiTRgCwQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-18 07:22:19
(21 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 07:13:58
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:13:53.605004 2026] [security2:error] [pid 29775:tid 29775] [client 89.140.181.213:54924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fetchamreadingroom.org"] [uri "/.env"] [unique_id "aqzksd8XwoDoiw1kheb3GwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
openstrike.co.uk
2026-09-18 05:14:14
(23 hours ago)
2 attacks on env grabbing URLs:
GET /.env HTTP/1.1
Hacking
πΊπΈ
TPI-Abuse
2026-09-18 03:50:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:50:00.147915 2026] [security2:error] [pid 32142:tid 32142] [client 89.140.181.213:54574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmlogistics.com"] [uri "/.env"] [unique_id "aqy06E4QJAu98xQx1T0sRAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 03:29:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:29:44.012314 2026] [security2:error] [pid 4449:tid 4570] [client 89.140.181.213:52202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellicottville.net"] [uri "/.env"] [unique_id "aqywKPXarE2eLkmCwCD3-wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΊ
DZBOT
2026-09-18 03:05:28
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-18 02:31:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono. ...
show more
(mod_security) mod_security (id:210492) triggered by 89.140.181.213 (89.140.181.213.static.user.ono.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:31:07.436400 2026] [security2:error] [pid 25101:tid 25101] [client 89.140.181.213:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eddysgroup.com"] [uri "/.env"] [unique_id "aqyiaz7KGga1KmtaZe_5cQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
β¨
2026-09-18 01:31:08
(1 day ago)
Domain : redirect.netenergy.uk
Rule : env
2026-09-18 01:29:23 217.194.210.152 GET /.env - 443 - 89.1 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-09-18 01:29:23 217.194.210.152 GET /.env - 443 - 89.140.181.213 HTTP/1.1 Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0 - drrogers.co.uk 404 0 2 1551 176 38 - -
show less
Hacking
SQL Injection