π©πͺ
big-cloud.nl
2026-08-24 05:47:20
(20 hours ago)
Try to access /.git/config
Web App Attack
π«π·
dynamix
2026-08-24 01:43:32
(1 day ago)
Multiple WAF Violations
Web App Attack
π§πͺ
cmbplf
2026-08-23 18:30:40
(1 day ago)
2.076 requests with url.path *.env
377 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-23 15:35:36
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.c ...
show more
(mod_security) mod_security (id:949110) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:35:29.218358 2026] [security2:error] [pid 23984:tid 23984] [client 15.156.85.253:55804] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.auranet.cescfoundation.org"] [uri "/.git/config"] [unique_id "aosTQULPPHTcYI8r3tEWOgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
maxxsense
2026-08-23 05:40:56
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 15.156.85.253 (CA/Canada/ec2-15-156-85- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 15.156.85.253 (CA/Canada/ec2-15-156-85-253.ca-central-1.compute.amazonaws.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-23 05:31:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:31:20.909096 2026] [security2:error] [pid 6441:tid 6441] [client 15.156.85.253:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chaitanyaconsult.in"] [uri "/.git/config"] [unique_id "aoqFqAJfSJCPz_XDpgF1pwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 05:03:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:03:05.449447 2026] [security2:error] [pid 13137:tid 13137] [client 15.156.85.253:54150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.audioadds.com.davisound.com"] [uri "/.git/config"] [unique_id "aop_CR_ei-0jhIXlH1dAIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-23 04:55:02
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π©πͺ
IVski.com
2026-08-22 21:22:43
(2 days ago)
IVski WAF | Git credentials probe - requesting /.git/config to read repository data
DDoS Attack
Bad Web Bot
π«π·
dynamix
2026-08-22 21:21:40
(2 days ago)
Multiple WAF Violations
Web App Attack
π«π·
Octopuce
2026-08-22 16:40:18
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
π©πͺ
gadix
2026-08-22 16:19:07
(2 days ago)
[22/Aug/2026:18:19:06.164771 +0200] aonL-oKdr8v5OfVgrioY4gAAAAE 15.156.85.253 43012 127.0.0.1 7081
[ ...
show more
[22/Aug/2026:18:19:06.164771 +0200] aonL-oKdr8v5OfVgrioY4gAAAAE 15.156.85.253 43012 127.0.0.1 7081
[22/Aug/2026:18:19:06.483232 +0200] aonL-tXdQ8QMJ_T21IcKkgAAAEE 15.156.85.253 43018 127.0.0.1 7081
[22/Aug/2026:18:19:06.696094 +0200] aonL-oKdr8v5OfVgrioY4wAAABA 15.156.85.253 43030 127.0.0.1 7081
...
show less
Web App Attack
π³π±
Site.eu
2026-08-22 12:14:05
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-08-22 03:55:02
(2 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 01:15:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 15.156.85.253 (ec2-15-156-85-253.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 21:15:14.382883 2026] [security2:error] [pid 31734:tid 31734] [client 15.156.85.253:56032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.app.oxfordgliding.com"] [uri "/.git/config"] [unique_id "aoj4Ii7g1K29VkpiL6eD4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack