π³π±
homeshowdomain.nl
2026-07-27 21:59:49
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 19:11:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:11:28.822404 2026] [security2:error] [pid 4023857:tid 4023857] [client 3.133.157.132:48352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pinetreedistrict.rimaine.org"] [uri "/.git/config"] [unique_id "ametYPPB9cEXR0Z1NA5-QwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 16:16:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:16:32.529704 2026] [security2:error] [pid 30231:tid 30231] [client 3.133.157.132:52820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piments.com.catking.net"] [uri "/.git/config"] [unique_id "ameEYIHykngJyTB9f62DTQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-07-27 13:02:12
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-27 11:06:08
(1 day ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (41/60 min)'; Requests=41
Port Scan
π«π·
Octopuce
2026-07-27 08:35:21
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 08:21:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:21:48.362451 2026] [security2:error] [pid 4140909:tid 4140909] [client 3.133.157.132:58330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pictures.pittyvaich.com"] [uri "/.git/config"] [unique_id "amcVHG8NKMTjc7BH6_2J9QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-07-27 08:05:29
(1 day ago)
Scanning/Probing (20)
Brute-Force
Web App Attack
Anonymous
2026-07-27 07:49:38
(1 day ago)
(caddyscan) Scanner path probe from 3.133.157.132 (US/United States/ec2-3-133-157-132.us-east-2.comp ...
show more
(caddyscan) Scanner path probe from 3.133.157.132 (US/United States/ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.133.157.132 - - [27/Jul/2026:07:49:34 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.133.157.132 - - [27/Jul/2026:07:49:34 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.133.157.132 - - [27/Jul/2026:07:49:34 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.133.157.132 - - [27/Jul/2026:07:49:34 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.133.157.132 - - [27/Jul/2026:07:49:34 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
π¬π§
consul.to
2026-07-27 07:31:41
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
debestelapp
2026-07-27 07:30:05
(1 day ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 05:19:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:18:57.491183 2026] [security2:error] [pid 2888889:tid 2888889] [client 3.133.157.132:47352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piccolofritto.hakkawok.com"] [uri "/.git/config"] [unique_id "ambqQQyNAXJ8-6vOl4p2twAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-07-27 05:07:28
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 04:30:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.133.157.132 (ec2-3-133-157-132.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:29:55.771852 2026] [security2:error] [pid 1919053:tid 1919064] [client 3.133.157.132:51782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piazzala.piazza9.com"] [uri "/.git/config"] [unique_id "ambew-2oa-MZ6LVjXdenzwAAAYM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-26 02:47:33
(3 days ago)
Multiple WAF Violations
Web App Attack