Anonymous
2026-07-29 07:00:00
(2 months ago)
Apache probe; attempts=445; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=445; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
πΊπΈ
kosada.com
2026-07-27 22:50:46
(2 months ago)
Web vulnerability probing: /api/dev/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 22:09:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:09:38.788284 2026] [security2:error] [pid 31308:tid 31308] [client 13.215.190.35:50540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stringview.antech.net"] [uri "/.git/config"] [unique_id "amfXIlU3h1X9zxIN3jZMUAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-27 22:00:56
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
Web App Attack
SSH
Hacking
πΏπ¦
conure.sh
2026-07-27 18:08:22
(2 months ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
π³π±
Site.eu
2026-07-27 11:57:23
(2 months ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-27 11:31:30
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:31:23.036998 2026] [security2:error] [pid 88612:tid 88612] [client 13.215.190.35:39334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stradcompetition.finestringinstruments.com"] [uri "/.git/config"] [unique_id "amdBi3DlwycDg1zrashzcQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-26 21:59:16
(2 months ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking
π±π»
garmtech.com
2026-07-26 01:53:26
(2 months ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
πΊπΈ
TPI-Abuse
2025-05-15 10:26:47
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 06:26:43.147431 2025] [security2:error] [pid 2607586:tid 2607586] [client 13.215.190.35:59480] [client 13.215.190.35] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.env"] [unique_id "aCXBY7UrJYs6Wx6YW_PzHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
ds6.net
2024-11-21 03:30:13
(1 year ago)
Blocked by CSF Firewall. Reason: lfd: (mod_security) mod_security (id:210730) triggered by 13.215.19 ...
show more
Blocked by CSF Firewall. Reason: lfd: (mod_security) mod_security (id:210730) triggered by 13.215.190.35 (SG/Singapore/ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 5 in the last 3600 secs - Thu Oct 17 00:12:43 2024
show less
Hacking
π©πͺ
mondor.ro
2024-10-17 12:17:31
(1 year ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 13.215.190.35, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 13.215.190.35, Reason:[(mod_security) mod_security (id:210730) triggered by 13.215.190.35 (SG/Singapore/ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
Anonymous
2024-10-17 11:26:00
(1 year ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-10-17 10:14:44
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210730) triggered by 13.215.190.35 (ec2-13-215-190-35.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 17 06:14:37.870818 2024] [security2:error] [pid 22808:tid 22808] [client 13.215.190.35:45860] [client 13.215.190.35] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sptzr.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sptzr.net"] [uri "/config/php.ini"] [unique_id "ZxDjjbNtvqOxdQxdwKdlvgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-10-17 07:16:11
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH