๐ณ๐ฑ
Site.eu
2026-07-25 04:39:06
(21 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
barbarella
2026-07-25 01:07:32
(1 day ago)
Multiple (273) times attack on https port 443: Illegal http header (POST /)
03:07:33 Illegal http ...
show more
Multiple (273) times attack on https port 443: Illegal http header (POST /)
03:07:33 Illegal http header (POST /)
03:07:33 hacking attempt of version control system (GET /.git/config)
03:07:34 Configuration snooping with .env file (GET /.env)
03:07:34 Configuration snooping with modified .env.* file (GET /.env.local)
03:07:34 Configuration snooping with modified .env.* file (GET /.env.production)
03:07:34 Configuration snooping with modified .env.* file (GET /.env.staging)
03:07:34 Configuration snooping with modified .env.* file (GET /.env.development)
03:07:34 Configuration snooping with modified .env.* file (GET /.env.test)
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 21:59:20
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 12:11:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:11:43.561182 2026] [security2:error] [pid 2339774:tid 2339774] [client 16.59.41.9:49178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canonarizona.com"] [uri "/.git/config"] [unique_id "amNWf_Up1cJReHBGdbuGygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-24 09:36:40
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:29:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:29:06.961736 2026] [security2:error] [pid 2420514:tid 2420514] [client 16.59.41.9:37384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cancersquared.com"] [uri "/.git/config"] [unique_id "amMwYrF085oqsreDg81nugAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:58:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:58:23.558330 2026] [security2:error] [pid 6571:tid 6571] [client 16.59.41.9:56122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canarysuites.com"] [uri "/.git/config"] [unique_id "amMpL_AQoa929ZYQP5kWrQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:00:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:00:52.384518 2026] [security2:error] [pid 290528:tid 290528] [client 16.59.41.9:38384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canadagreenrecycling.com"] [uri "/.git/config"] [unique_id "amMbtJhc3L2aTjfXwINxIQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-07-24 06:39:25
(1 day ago)
http-sensitive-files - IP: 16.59.41.9 - time="2026-07-24T08:39:25+02:00" level=info msg="(555f66b4f ...
show more
http-sensitive-files - IP: 16.59.41.9 - time="2026-07-24T08:39:25+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 16.59.41.9 (US/0) : 4h ban on Ip 16.59.41.9" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:39:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:39:02.262826 2026] [security2:error] [pid 3861080:tid 3861080] [client 16.59.41.9:37686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "campnecon.com"] [uri "/.git/config"] [unique_id "amMIhsnx-dizCeyudQ8jTwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:15:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:15:16.156898 2026] [security2:error] [pid 501938:tid 501961] [client 16.59.41.9:53032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "campingcosmetics.com"] [uri "/.git/config"] [unique_id "amMC9LiUl2r1sCV9ZPb9gQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 06:00:06
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-24 05:57:08
(1 day ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:33:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:33:16.667374 2026] [security2:error] [pid 3443436:tid 3443436] [client 16.59.41.9:47386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "campbellsclan.com"] [uri "/.git/config"] [unique_id "amL5HHttX7Mo-2WYjv7yIwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:01:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.am ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.41.9 (ec2-16-59-41-9.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:01:24.195633 2026] [security2:error] [pid 15753:tid 15753] [client 16.59.41.9:56634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "camouflagebikinis.com"] [uri "/.git/config"] [unique_id "amLxpJiv5i3RU5Crpmm_ogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack