|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
|
Exploited Host
Web App Attack
|
|
|
๐ช๐ธ
boscolopez
|
|
13.212.119.181 - - [16/Nov/2025:08:14:11 +0100] "GET /.env HTTP/1.1" 403 146 "-" "python-httpx/0.24. ...
show more
13.212.119.181 - - [16/Nov/2025:08:14:11 +0100] "GET /.env HTTP/1.1" 403 146 "-" "python-httpx/0.24.1" "0.000" "-"
...
show less
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 01:57:30.363864 2025] [security2:error] [pid 27523:tid 27523] [client 13.212.119.181:60946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkmediasoftware.com"] [uri "/.env.dev"] [unique_id "aRl12lQxlaHXZBwlJROvJAAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Savvii
|
|
20 attempts against mh_ha-misbehave-ban on bush
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
oralunal
|
|
IP banned by Fail2Ban in jail its-suss access.log mvfnds
...
|
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 14:58:09.875329 2025] [security2:error] [pid 31845:tid 31845] [client 13.212.119.181:44622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oficinasydespachosmurcia.com"] [uri "/.env"] [unique_id "aRjbUUf8rS_PVLJ2QAPU7wAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 08:34:59.714078 2025] [security2:error] [pid 800:tid 802] [client 13.212.119.181:49436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nomoreamericanwar.onenessrecords.com"] [uri "/.env"] [unique_id "aRiBgwClbxi9FrudpvBSRAAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 22:42:20.548128 2025] [security2:error] [pid 32519:tid 32519] [client 13.212.119.181:49226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suswastima.com"] [uri "/.git/config"] [unique_id "aRf2nAgwWfkTbtHniTFwiQAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 15:19:20.883237 2025] [security2:error] [pid 17451:tid 17451] [client 13.212.119.181:42988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trailofcrumbs.com"] [uri "/.git/config"] [unique_id "aReOyFyvZfv_st9-6qvOIwAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 14:25:36.555970 2025] [security2:error] [pid 2220664:tid 2220664] [client 13.212.119.181:51548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedieselgroupllc.com"] [uri "/.git/config"] [unique_id "aReCMGBb324zV3TSv5Ex8gAAABM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.119.181 (ec2-13-212-119-181.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 12:17:08.208113 2025] [security2:error] [pid 5119:tid 5119] [client 13.212.119.181:35908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewarmachineguns.com"] [uri "/.git/config"] [unique_id "aRdkFALP-KRmgrq9gBLSGQAAABY"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|