🇺🇸
TPI-Abuse
2026-09-04 07:06:39
(56 minutes ago)
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:06:30.450624 2026] [security2:error] [pid 12253:tid 12253] [client 18.203.115.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomworkforceoptimization.com"] [uri "/.git/config"] [unique_id "appt9sg-hL7DhJhVcDbd1AAAAAs"], referer: https://www.google.com/search?q=wisdomworkforceoptimization.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Progetto1
2026-09-04 06:53:02
(1 hour ago)
Detected via HAProxyScanner at 2026-09-04 06:53:02 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-09-04 06:53:02 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
🇩🇪
pltcldvlpr
2026-09-04 06:07:00
(1 hour ago)
CMS/framework probe: 18.203.115.34 - - [04/Sep/2026:08:06:58 +0200] "GET /secrets.json HTTP/1.1" 404 ...
show more
CMS/framework probe: 18.203.115.34 - - [04/Sep/2026:08:06:58 +0200] "GET /secrets.json HTTP/1.1" 404 564 "https://worker-bold-mud-d6d0.xiaomai03736.workers.dev/proxy?modify&proxyUrl=https%3A%2F%2Fstudentenchronik.de%2Fsecrets.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36" asn=16509 org="Amazon.com, Inc." country=IE
...
show less
Web App Attack
Anonymous
2026-09-04 03:55:01
(4 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
Bedios GmbH
2026-09-04 03:13:30
(4 hours ago)
Login credentials theft attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 03:01:48
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:01:41.879034 2026] [security2:error] [pid 17718:tid 17718] [client 18.203.115.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "graduationpartynapkins.com"] [uri "/.env"] [unique_id "apo0lZlW376FmzZbMB1WLgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-04 01:30:13
(6 hours ago)
Domain : devportal.igbocommunitycoventry.org
Rule : env
2026-09-04 01:28:19 ***hidden-privacy*** GET ...
show more
Domain : devportal.igbocommunitycoventry.org
Rule : env
2026-09-04 01:28:19 ***hidden-privacy*** GET /.env.old - 443 - 162.158.6.71 HTTP/2 Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.4 Safari/605.1.15 - devportal.igbocommunitycoventry.org 404 0 2 1137 585 62 - 18.203.115.34
show less
Hacking
SQL Injection
🇳🇱
homeshowdomain.nl
2026-09-03 22:00:22
(10 hours ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-03 19:41:33
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:41:27.444639 2026] [security2:error] [pid 1591163:tid 1591253] [client 18.203.115.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.starlinksales.net.exede-sales.com"] [uri "/.env.production"] [unique_id "apnNZ77tXB9Anvi7OzSlxAAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-03 19:01:12
(13 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:01:45
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.203.115.34 (ec2-18-203-115-34.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:01:37.263148 2026] [security2:error] [pid 30510:tid 30510] [client 18.203.115.34:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ncparanormalresearch.com"] [uri "/.env.backup"] [unique_id "apmZ4ZFr7ILbjISV1toaOwAAABQ"], referer: https://www.google.com/search?q=ncparanormalresearch.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-09-03 15:50:38
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇨🇭
backslash
2026-09-03 15:12:00
(16 hours ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
🇺🇸
MPL
2026-09-01 02:02:09
(3 days ago)
tcp/443 (2 or more attempts)
Port Scan
🇨🇦
Anytech
2026-08-31 20:42:06
(3 days ago)
Blocked by ConnMonitor: Bad Bot
Bad Web Bot
Spoofing