๐ณ๐ฑ
Site.eu
2026-05-15 09:32:18
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Site.eu
2026-05-13 23:06:07
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
AutoAddOnStore
2026-05-13 17:54:00
(4 months ago)
Excessive crawling
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 14:16:03
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): ...
show more
(mod_security) mod_security (id:949110) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 10:15:59.471570 2026] [security2:error] [pid 12498:tid 12498] [client 2a02:4780:75:8487::1:33740] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "auranet.cescfoundation.org"] [uri "/api/.env"] [unique_id "agSHn_PK9gEDh5zMmpstvwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 08:20:25
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 04:20:22.720434 2026] [security2:error] [pid 15791:tid 15791] [client 2a02:4780:75:8487::1:43088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesilverlegion.org.communityofthecosmos.org"] [uri "/.git/HEAD"] [unique_id "agQ0RlXqXsHXpjjwUQS7ngAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-05-13 07:56:03
(4 months ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Macintosh; Intel Mac OS ...
show more
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 05:46:46
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 01:46:38.793299 2026] [security2:error] [pid 1438:tid 1438] [client 2a02:4780:75:8487::1:41852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tecnoconce.tecnoconce.com"] [uri "/.env.production"] [unique_id "agQQPmHr2KPBbxDPUYIbQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 04:41:29
(4 months ago)
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /.git/HEAD HTTP/1.1" 403 153 "-" "Mozilla ...
show more
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /.git/HEAD HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15_7_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/26.0 Safari/605.1.15"
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /backend/.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15.7; rv:149.0) Gecko/20100101 Firefox/149.0"
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 15.7; rv:149.0) Gecko/20100101 Firefox/149.0"
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /.env.local HTTP/1.1" 403 153 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
2a02:4780:75:8487::1 - - [13/May/2026:01:41:28 -0300] "GET /.env.production HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-13 01:53:58
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 21:53:54.030370 2026] [security2:error] [pid 24184:tid 24184] [client 2a02:4780:75:8487::1:54082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.oowoah.com"] [uri "/.git/config"] [unique_id "agPZsljddKJ7weRNFeikfQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-12 22:35:15
(4 months ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-05-12 22:31:59
(4 months ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 20:08:44
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:75:8487::1 (srv1657850.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 16:08:39.873270 2026] [security2:error] [pid 16389:tid 16406] [client 2a02:4780:75:8487::1:42268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vnonnonprofit.org"] [uri "/.git/HEAD"] [unique_id "agOIx5QpTGCSbl52pvCIsAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-05-12 19:55:53
(4 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ช๐ธ
antivoid.xyz
2026-05-12 18:19:28
(4 months ago)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-05-12 17:55:28
(4 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack