๐ง๐ช
cmbplf
2026-07-29 18:37:55
(1 hour ago)
2.308 requests with url.path *.env
289 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
Anonymous
2026-07-29 14:08:49
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 13:34:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 09:34:39.562372 2026] [security2:error] [pid 3242105:tid 3242105] [client 165.245.186.104:44796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crystalvisionsart.com"] [uri "/.git/config"] [unique_id "amoBb3JEq9WVBzw70zAbEQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(13 hours ago)
Apache probe; attempts=402; exact paths: /.env | /.env.backup | /.env.bak | /.env.ci | /.env.dev | / ...
show more
Apache probe; attempts=402; exact paths: /.env | /.env.backup | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.uat | /.env~ | /.git/config | /admin/.env | /administrator/.env | /api/.env | /api/v1/.env | /api/v2/.env | /app/.env | /apps/.env | /assets/.env | /backend/.env | /backup/.env | /backups/.env | /brevo/.env | /build/.env | /bulk/.env | /campaign/.env | /client/.env | /cms/.env | /config/.env | /core/.env | /core/Database/.env | /core/app/.env | /crm/.env | /cron/.env | /cronlab/.env | /current/.env | /dashboard/.env | /database/.env | /deploy/.env | /dev/.env | /dist/.env | /drupal/.env | /email/.env | /en/.env | /erp/.env | /exapi/.env | /express/.env | /front | ... [134 exact paths total]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 06:27:01
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 02:26:55.211687 2026] [security2:error] [pid 8921:tid 8921] [client 165.245.186.104:45340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruanyes.com"] [uri "/.git/config"] [unique_id "ammdL9NGthQ--2z7wKs0iwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 04:21:21
(15 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
tsZero
2026-07-29 04:18:03
(15 hours ago)
Scan example: path=/.git/config status=401
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-29 02:05:35
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 22:05:28.377265 2026] [security2:error] [pid 3231559:tid 3231559] [client 165.245.186.104:57872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crossfiregold.com"] [uri "/.git/config"] [unique_id "amlf6N021luGfBGRoNzbtAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 21:14:39
(22 hours ago)
165.245.186.104 - - [28/Jul/2026:21:14:38 +0000] "GET /.git/config HTTP/1.1" 403 468 "-" "Mozilla/5. ...
show more
165.245.186.104 - - [28/Jul/2026:21:14:38 +0000] "GET /.git/config HTTP/1.1" 403 468 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-28 12:08:18
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Cuteminded
2026-07-28 04:50:50
(1 day ago)
Hit honeypot endpoint
Web App Attack
๐ซ๐ท
Pays d'Angoulรชme
2026-07-28 00:56:14
(1 day ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /info.php
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-27 19:10:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:49:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 165.245.186.104 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:49:39.416215 2026] [security2:error] [pid 4113228:tid 4113228] [client 165.245.186.104:47848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.secemexico.com.disenowebprofesional.com"] [uri "/.git/config"] [unique_id "amdwAx8yMKVvpkaR2k7MYAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 06:43:01
(2 days ago)
Excessive multi-domain requests
Brute-Force