๐จ๐ฆ
ISPLtd
2025-09-27 00:28:20
(11 months ago)
Hacking, URL manipulation, malformed requests, or requests for invalid/hidden files like .git/config ...
show more
Hacking, URL manipulation, malformed requests, or requests for invalid/hidden files like .git/config or .env.
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-09-14 21:59:03
(11 months ago)
Auto-ban: >500 bad req/min on 2025-09-13
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-09-14 05:56:46
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 01:56:38.965132 2025] [security2:error] [pid 8383:tid 8383] [client 13.41.64.102:32942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "premierveterinarysurgery.com"] [uri "/.env"] [unique_id "aMZZFjBNrGXxK5FPJYeZLgAAABY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-14 05:50:22
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_MODSEC
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-09-14 04:30:46
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 14 00:30:42.094796 2025] [security2:error] [pid 6770:tid 6770] [client 13.41.64.102:45866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "predeity.autobee.biz"] [uri "/.env"] [unique_id "aMZE8kPrfDRbsBXYV5YbaQAAAAY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-09-14 04:23:41
(11 months ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
zorrigas
2025-09-13 22:10:07
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (GB/United Kingdom/ec2-13-41-64-10 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (GB/United Kingdom/ec2-13-41-64-102.eu-west-2.compute.amazonaws.com): 5 in the last 3600 secs
show less
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2025-09-13 21:59:11
(11 months ago)
Auto-ban: >3000 req/min op 2025-09-13
Hacking
Web App Attack
SSH
Anonymous
2025-09-13 21:20:24
(11 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ฆ
ISPLtd
2025-09-13 20:17:41
(11 months ago)
13.41.64.102 - - [13/Sep/2025:17:17:37 -0300] "GET /.env
13.41.64.102 - - [13/Sep/2025:17:17:41 -030 ...
show more
13.41.64.102 - - [13/Sep/2025:17:17:37 -0300] "GET /.env
13.41.64.102 - - [13/Sep/2025:17:17:41 -0300] "GET /.env
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2025-09-13 19:17:36
(11 months ago)
20 attempts against mh-misbehave-ban on cell
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-09-13 19:16:20
(11 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 07:57:21
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 02:57:16.713863 2023] [security2:error] [pid 12088] [client 13.41.64.102:51214] [client 13.41.64.102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.xn--lyngr-yua.net"] [uri "/wp-config.php"] [unique_id "ZVcc3PeTqUkzbCV8OurDwQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-17 07:39:17
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 13.41.64.102 (ec2-13-41-64-102.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 17 02:39:14.470088 2023] [security2:error] [pid 21097:tid 47333994428160] [client 13.41.64.102:42310] [client 13.41.64.102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "securitymediaservices.com"] [uri "/wp-config.php"] [unique_id "ZVcYojxZBrjyFSicKy12bgAAAcg"]
show less
Brute-Force
Bad Web Bot
Web App Attack