πΊπΈ
Lee Daniel
2026-07-25 20:49:46
(7 hours ago)
18.208.223.86 - - [25/Jul/2026:16:49:46 -0400] "GET /.env HTTP/1.1" 403 6295 "-" "Mozilla/5.0 (Windo ...
show more
18.208.223.86 - - [25/Jul/2026:16:49:46 -0400] "GET /.env HTTP/1.1" 403 6295 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-07-25 19:05:05
(9 hours ago)
Too many Status 40X (91)
Scanning/Probing (91)
Brute-Force
Web App Attack
π±π»
garmtech.com
2026-07-25 07:15:19
(21 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
π§πͺ
taivas.nl
2026-07-25 04:33:35
(23 hours ago)
Many_bad_calls
Web App Attack
πΊπΈ
juguemosalacarioca.com
2026-07-25 03:33:00
(1 day ago)
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port ...
show more
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port 8080
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 23:51:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:51:25.670289 2026] [security2:error] [pid 1429013:tid 1429013] [client 18.208.223.86:57070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbar.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "amP6fRv2rwlJUZokdrMcwAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-24 21:59:43
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-24 17:24:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:23:56.190526 2026] [security2:error] [pid 2298808:tid 2298808] [client 18.208.223.86:59676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.just4uscrubs.quickasawink.org|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.just4uscrubs.quickasawink.org"] [uri "/.env.bak"] [unique_id "amOfrFglL3ba7vvfm6sj9wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-07-24 16:31:23
(1 day ago)
Excessive 404/403 errors
Brute-Force
π§πͺ
taivas.nl
2026-07-24 15:32:11
(1 day ago)
Bad_requests
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-24 14:12:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:12:23.202407 2026] [security2:error] [pid 3620883:tid 3620883] [client 18.208.223.86:52424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juniperhills.davidwoodard.com"] [uri "/.git/config"] [unique_id "amNyx6_SdXD_89SkNeQWzQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 07:54:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:54:28.101273 2026] [security2:error] [pid 3587536:tid 3587536] [client 18.208.223.86:46028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juicequeen.benshermanguitar.com"] [uri "/.git/config"] [unique_id "amMaNJ1my26eJWVuj1UDVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
juguemosalacarioca.com
2026-07-24 07:32:20
(1 day ago)
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port ...
show more
Multiple HTTP calls attempting to GET resources using common/malformed API calls or formats on port 8080
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 04:05:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 18.208.223.86 (ec2-18-208-223-86.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:05:21.415756 2026] [security2:error] [pid 97340:tid 97359] [client 18.208.223.86:34456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.juantrece.emehache.net"] [uri "/.git/config"] [unique_id "amLkgcQghD1gTYVCFZxK3wAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-30 00:40:17
(2 years ago)
$f2bV_matches
Brute-Force
SSH