|
๐ณ๐ฑ
homeshowdomain.nl
|
|
Auto-ban: >3000 req/min op 2026-08-23
|
Web App Attack
SSH
Hacking
|
|
|
๐ซ๐ท
bazter.pro
|
|
Auto-Ban [2026-08-23 08:06:17]: CRITICAL: .env attack; DC: Amazon Data Services India [Paths: 272] | ...
show more
Auto-Ban [2026-08-23 08:06:17]: CRITICAL: .env attack; DC: Amazon Data Services India [Paths: 272] | Details: Exploit trap paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | Sensitive files/paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | 404 errors (276): /phpinfo.php.old, /sender/.env, /releases/.env, /live/.env, /microservice/.env, /cronlab/.env, /rabbitmq/.env, /var/www/.env, /k8s/.env, /test/.env (and 262 more)
show less
|
Web App Attack
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:949110) triggered by 3.110.194.27 (ec2-3-110-194-27.ap-south-1.compu ...
show more
(mod_security) mod_security (id:949110) triggered by 3.110.194.27 (ec2-3-110-194-27.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:13:51.031412 2026] [security2:error] [pid 6269:tid 6269] [client 3.110.194.27:50488] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.blog.freedrm.org"] [uri "/.git/config"] [unique_id "aopzf7VYTveFW6v2fYK5GgAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Site.eu
|
|
Excessive 404/403 errors
|
Brute-Force
|
|
|
๐ง๐ช
cmbplf
|
|
151 requests with url.path *credentials.json
|
Brute-Force
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 3.110.194.27 (ec2-3-110-194-27.ap-south-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.110.194.27 (ec2-3-110-194-27.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 22:16:18.922540 2026] [security2:error] [pid 27436:tid 27436] [client 3.110.194.27:34534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blockadefoundationrepair.weyoungrenovations.com"] [uri "/.git/config"] [unique_id "aopX8sgQ0Pvz2fqc1TXfWAAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Multiple web server 400 error codes from same source ip
|
Web App Attack
|
|
|
๐ฌ๐ง
blik2108
|
|
www.blacknellfamilyhistory.co.uk:443 3.110.194.27 - - [22/Aug/2026:20:27:56 +0100] "GET /.git/config ...
show more
www.blacknellfamilyhistory.co.uk:443 3.110.194.27 - - [22/Aug/2026:20:27:56 +0100] "GET /.git/config HTTP/1.1" 404 573 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 3.110.194.27 - - [22/Aug/2026:20:27:56 +0100] "GET /.env HTTP/1.1" 404 42247 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 3.110.194.27 - - [22/Aug/2026:20:27:56 +0100] "GET /.env.local HTTP/1.1" 404 42247 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 3.110.194.27 - - [22/Aug/2026:20:27:57 +0100] "GET /.env.production HTTP/1.1" 404 42247 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 3.110.194.27
...
show less
|
Brute-Force
|
|