π«π·
breubit
2026-07-17 21:38:40
(1 week ago)
13.38.137.160 - - [17/Jul/2026:23:38:39 +0200] "GET /.git/config HTTP/1.1" 404 514 "-" "Mozilla/5.0 ...
show more
13.38.137.160 - - [17/Jul/2026:23:38:39 +0200] "GET /.git/config HTTP/1.1" 404 514 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
π©πͺ
updown.io
2026-07-17 20:48:51
(1 week ago)
{"level":"info","ts":1784321325.1690772,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1784321325.1690772,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"13.38.137.160","remote_port":"46714","client_ip":"13.38.137.160","proto":"HTTP/1.1","method":"GET","host":"delivery.status.adnuntius.com","uri":"/.env.development","headers":{"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"],"Connection":["keep-alive"],"Next-Action":["x"],"X-Nextjs-Request-Id":["35eb78b1"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"delivery.status.adnuntius.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000515845,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1784321325.1799216,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"13.38.137.160",
...
show less
DDoS Attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 01:24:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:24:24.153144 2026] [security2:error] [pid 68591:tid 68591] [client 13.38.137.160:43738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mbehel.com"] [uri "/.git/config"] [unique_id "almESFvGgkt_ZT88WseOpgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-16 22:03:04
(1 week ago)
Auto-ban: >3000 req/min op 2026-07-16
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2025-10-01 07:19:36
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 03:19:33.146917 2025] [security2:error] [pid 21456:tid 21456] [client 13.38.137.160:56974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alterationsbylinh.linhsbridal.com"] [uri "/.env"] [unique_id "aNzWBRINXm1h6hVSHILJAgAAAAQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-01 06:59:00
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 02:58:54.393938 2025] [security2:error] [pid 23649:tid 23649] [client 13.38.137.160:46332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "althea.seizetheseason.com"] [uri "/.env"] [unique_id "aNzRLnadYiBBeXtj4IYbVQAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-10-01 06:41:18
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 02:41:13.660333 2025] [security2:error] [pid 7546:tid 7566] [client 13.38.137.160:44040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alfred.merart.com"] [uri "/.env"] [unique_id "aNzNCS_KWf1EtORYK8-JgAAAAJA"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-01 06:26:05
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-10-01 06:12:12
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 02:12:06.471092 2025] [security2:error] [pid 3041:tid 3041] [client 13.38.137.160:37032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alecmcatee.robertmcatee.com"] [uri "/.env"] [unique_id "aNzGNmG_kZeeY5byiorlIwAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-01 06:08:33
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2025-10-01 05:48:09
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 13.38.137.160 (ec2-13-38-137-160.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 01:48:04.620982 2025] [security2:error] [pid 4828:tid 4828] [client 13.38.137.160:43164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agrizel.menagri.com"] [uri "/.env"] [unique_id "aNzAlNcwPh6hkO5MWRmk9gAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2025-10-01 04:10:22
(9 months ago)
Probing for application vulnerabilities
Brute-Force
Web App Attack