Anonymous
2026-07-17 22:24:55
(2 days ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.mdlab-ntua.gr; logs=/var/log/httpd/domains/mdlab-ntua.gr ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.mdlab-ntua.gr; logs=/var/log/httpd/domains/mdlab-ntua.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
Anonymous
2026-07-17 09:21:30
(3 days ago)
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.com ...
show more
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:09:21:27 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:09:21:27 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:09:21:27 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:09:21:28 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:09:21:28 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-17 03:12:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:12:33.699105 2026] [security2:error] [pid 3945718:tid 3945718] [client 3.106.116.246:59048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davisllp.com"] [uri "/.git/config"] [unique_id "almdoXNmQB3NkWF5ZUAUPQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-07-17 03:05:57
(3 days ago)
(mod_security) mod_security (id:1000001) triggered by 3.106.116.246 (AU/Australia/New South Wales/Sy ...
show more
(mod_security) mod_security (id:1000001) triggered by 3.106.116.246 (AU/Australia/New South Wales/Sydney/-/[AS16509 AMAZON-02]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:05:56.951940 2026] [security2:error] [pid 499136:tid 499318] [client 3.106.116.246:35750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/p.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /p.php"] [severity "CRITICAL"] [tag "security"] [hostname "mail.davids.gr"] [uri "/p.php"] [unique_id "almcFFVGc4OXrB1cLLqLJQAAAJY"]
show less
Port Scan
Anonymous
2026-07-17 03:00:04
(3 days ago)
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.com ...
show more
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:03:00:01 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:03:00:02 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:03:00:02 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:03:00:02 +0000] "GET /.env.staging HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:03:00:03 +0000] "GET /.env.development HTTP/1.1"
show less
Port Scan
๐ฎ๐น
VHosting
2026-07-17 02:40:03
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-07-17 01:10:51
(3 days ago)
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.com ...
show more
(caddyscan) Scanner path probe from 3.106.116.246 (AU/Australia/ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:01:10:47 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:01:10:47 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:01:10:47 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:01:10:48 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.106.116.246 - - [17/Jul/2026:01:10:48 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-17 00:34:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 20:34:07.979640 2026] [security2:error] [pid 7613:tid 7654] [client 3.106.116.246:55566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.danbressler.com"] [uri "/.git/config"] [unique_id "all4f4krzV-ifcORUNszmQAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 18:52:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 3.106.116.246 (ec2-3-106-116-246.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 14:52:03.136503 2026] [security2:error] [pid 24297:tid 24297] [client 3.106.116.246:54650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.paladinmicro.com"] [uri "/.git/config"] [unique_id "alkoU61JNK2uS-Dkln9SGAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack