Anonymous
2026-07-29 07:00:00
(11 hours ago)
Automated Apache web application probing in selected 24h window; attempts=211, unique_paths=211, err ...
show more
Automated Apache web application probing in selected 24h window; attempts=211, unique_paths=211, error_responses=0; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(11 hours ago)
Apache probe; attempts=422; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=422; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
๐ญ๐บ
wickedip
2026-07-28 06:18:00
(1 day ago)
Multiple WAF violations. (Scanning for credential files, nonexistent PHP files, other hacker files, ...
show more
Multiple WAF violations. (Scanning for credential files, nonexistent PHP files, other hacker files, using fake and/or empty UserAgent values.)
show less
Brute-Force
Exploited Host
Web App Attack
Hacking
๐ฉ๐ช
netclix.gr
2026-07-28 03:02:50
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 18.117.135.230 (US/United States/ec2-18 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 18.117.135.230 (US/United States/ec2-18-117-135-230.us-east-2.compute.amazonaws.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
DocNetzwerk
2026-07-28 02:51:02
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 18.117.135.230 (US/United States/ec2-18 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 18.117.135.230 (US/United States/ec2-18-117-135-230.us-east-2.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-28 02:20:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:20:03.076889 2026] [security2:error] [pid 421090:tid 421090] [client 18.117.135.230:55310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hopeforthefuture.africa.greenlight.us"] [uri "/.git/config"] [unique_id "amgR01Fjitw4TOeVXeW8XgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-28 01:09:49
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
mnsf
2026-07-27 15:05:51
(2 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐ฉ๐ช
AetherFox
2026-07-27 14:44:35
(2 days ago)
AetherFox VoidGuard detected: [Mon Jul 27 14:44:34.488378 2026] [authz_core:error] [pid 2953925:tid ...
show more
AetherFox VoidGuard detected: [Mon Jul 27 14:44:34.488378 2026] [authz_core:error] [pid 2953925:tid 2953951] [client 18.117.135.230:59226] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Mon Jul 27 14:44:34.717389 2026] [authz_core:error] [pid 2953925:tid 2953947] [client 18.117.135.230:59226] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Mon Jul 27 14:44:34.833964 2026] [authz_core:error] [pid 2953925:tid 2953964] [client 18.117.135.230:59226] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Mon Jul 27 14:44:34.950295 2026] [authz_core:error] [pid 2953925:tid 2953968] [client 18.117.135.230:59226] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Mon Jul 27 14:44:35.068410 2026] [authz_core:error] [pid 2953925:tid 2953952] [client 18.117.135.230:59226] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git/config
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:48:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:48:26.103599 2026] [security2:error] [pid 432668:tid 432668] [client 18.117.135.230:44334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hppagewideprinting.com"] [uri "/.git/config"] [unique_id "amc3eqDyLx1v9jYoF7N4VwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 21:59:34
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 12:51:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 18.117.135.230 (ec2-18-117-135-230.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 08:51:24.252070 2026] [security2:error] [pid 2356917:tid 2356917] [client 18.117.135.230:46546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ratbird.com"] [uri "/.git/config"] [unique_id "amSxTKzZM2FpkmLX4yRxNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-25 10:25:05
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ญ
Ribeye375
2026-07-24 19:12:17
(4 days ago)
HIPS nginx-anti-botnet - Block tcp/0:65535
Bad Web Bot