Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=1523; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1523; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
Anonymous
2026-07-28 04:57:36
(1 month ago)
Aggressive web scan
Web App Attack
🇧🇪
madeit
2026-07-28 02:11:37
(1 month ago)
Web App Attack
Anonymous
2026-07-28 02:05:56
(1 month ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/appsec-vpatch; Action=ban; Events=2; Co ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/appsec-vpatch; Action=ban; Events=2; Country=SG; ASN=16509 AMAZON-02
show less
Hacking
Anonymous
2026-07-28 01:06:13
(1 month ago)
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Event ...
show more
IncogNET WAF local CrowdSec decision. Scenario=crowdsecurity/http-sensitive-files; Action=ban; Events=5; Hosts=portal.incognet.io; Paths=/.env,/.env.development,/.env.staging,/.env.test,/.git/config; Country=SG; ASN=16509 AMAZON-02
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 11:10:39
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:10:35.410696 2026] [security2:error] [pid 491040:tid 491040] [client 13.212.185.79:46892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prezence.com"] [uri "/.git/config"] [unique_id "amc8q1e0BLaDKSg50AFbxgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-07-24 22:01:09
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-07-24 21:54:16
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 17:54:13.278419 2026] [security2:error] [pid 1282450:tid 1282450] [client 13.212.185.79:36040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.liburumi.tucek.org"] [uri "/.git/config"] [unique_id "amPfBeJXrwV9iNv3EUFDZAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-24 16:12:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:11:56.092620 2026] [security2:error] [pid 401074:tid 401074] [client 13.212.185.79:41068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lhhs69.johnpritchett.com"] [uri "/.git/config"] [unique_id "amOOzBGyDhPsXOMCzWu9ZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-24 12:15:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:15:44.860253 2026] [security2:error] [pid 4110035:tid 4110035] [client 13.212.185.79:39454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lfrmtmorris.encoremtmorris.com"] [uri "/.git/config"] [unique_id "amNXcIZkmoaOzDWtudk1DQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-24 08:46:58
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.212.185.79 (ec2-13-212-185-79.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:46:51.072294 2026] [security2:error] [pid 1215667:tid 1215667] [client 13.212.185.79:52368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lexie.boens.org"] [uri "/.git/config"] [unique_id "amMme8-2LNVdA4zoMa9jRQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 07:05:13
(1 month ago)
Blocked: Reason='Vulnerability probing — PHP scan detected (41/60 min)'; Requests=41
Port Scan
🇮🇹
VHosting
2026-07-24 06:15:04
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack