π³π±
ReyhZhao
2026-07-27 10:32:02
(37 minutes ago)
Multiple ModSecurity access denials (HTTP 403) triggered by a high outbound anomaly score from a sin ...
show more
Multiple ModSecurity access denials (HTTP 403) triggered by a high outbound anomaly score from a single source IP, indicating potential malicious activity or policy violations.
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-27 05:44:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:44:35.975840 2026] [security2:error] [pid 1548388:tid 1548409] [client 3.120.228.120:34318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oneringnetwork.net"] [uri "/.git/config"] [unique_id "ambwQ7wTQAf3T_SDG8pZvwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-07-27 04:35:55
(6 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-07-26 21:59:32
(13 hours ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking
π©πͺ
big-cloud.nl
2026-07-26 08:22:16
(1 day ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-26 05:18:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 01:18:01.694919 2026] [security2:error] [pid 3399156:tid 3399156] [client 3.120.228.120:43150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourhotmail.com"] [uri "/.git/config"] [unique_id "amWYiQ0dez3oSdhoIrt3JgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-07-26 03:42:37
(1 day ago)
Excessive 404/403 errors
Brute-Force
π«π·
Octopuce
2026-07-26 03:08:27
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
π³π±
homeshowdomain.nl
2026-07-25 22:05:25
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-25 03:33:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:33:16.868165 2026] [security2:error] [pid 714875:tid 714875] [client 3.120.228.120:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsfwmanager.com"] [uri "/.env.txt"] [unique_id "amQufKyInMrBvgkffy8VRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SwinT
2026-07-25 03:00:05
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πͺπΈ
masterguru
2026-07-25 01:10:45
(2 days ago)
. Matched phrase "/.env" at REQUEST_URI. (210492-178)
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 11:00:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:00:28.809971 2026] [security2:error] [pid 3770817:tid 3770817] [client 3.120.228.120:57132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonesandbones.net"] [uri "/.git/config"] [unique_id "amNFzN_6dNTbWpBvT1UpMgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 10:13:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 3.120.228.120 (ec2-3-120-228-120.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:13:30.679188 2026] [security2:error] [pid 3808228:tid 3808239] [client 3.120.228.120:48288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stone-doyle.com"] [uri "/.git/config"] [unique_id "amM6yvEIn8JVdQ8tZK6LpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-07-24 09:59:37
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking