๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:00:13
(16 hours ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 21:05:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 17:05:02.462862 2026] [security2:error] [pid 2384813:tid 2384813] [client 3.135.202.169:43722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cthog.z-mgmt.com"] [uri "/.git/config"] [unique_id "amfH_nTjjVcIgvYg3mrNlQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsa
2026-07-27 18:06:00
(20 hours ago)
GET /wordpress/.env/ HTTP/1.1
DDoS Attack
Brute-Force
Exploited Host
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-07-27 17:52:58
(20 hours ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-07-27 16:00:05
(22 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:27:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:27:05.487402 2026] [security2:error] [pid 137705:tid 137705] [client 3.135.202.169:50254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.csf-pos.computerservicesofflorida.com"] [uri "/.git/config"] [unique_id "amdqueD59FLw4ohSesqNrwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-07-27 13:33:14
(1 day ago)
3.135.202.169 (US/United States/ec2-3-135-202-169.us-east-2.compute.amazonaws.com), more than 7 Apac ...
show more
3.135.202.169 (US/United States/ec2-3-135-202-169.us-east-2.compute.amazonaws.com), more than 7 Apache 403 hits
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 11:57:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:57:19.216713 2026] [security2:error] [pid 270265:tid 270265] [client 3.135.202.169:54334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cs.cswiki.us"] [uri "/.git/config"] [unique_id "amdHn0Nbk-rDLcUcpUlycQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:22:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:22:09.976418 2026] [security2:error] [pid 79146:tid 79146] [client 3.135.202.169:35964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crystalvisionsart.benshermanguitar.com"] [uri "/.git/config"] [unique_id "amc_YShjwTd_zpYj0YAvlwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 10:31:00
(1 day ago)
Bad behavior, scanning .env files
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-07-27 07:29:21
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-07-27 07:25:26
(1 day ago)
\[Mon Jul 27 09:25:25.711791 2026\] \[:error\] \[pid 27818:tid 139785779762944\] \[client 3.135.202. ...
show more
\[Mon Jul 27 09:25:25.711791 2026\] \[:error\] \[pid 27818:tid 139785779762944\] \[client 3.135.202.169:59472\] \[client 3.135.202.169\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 10\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.crx.it"\] \[uri "/"\] \[unique_id "amcH5fzW9qeUMxjyyYiz7AAAAEw"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:02:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.135.202.169 (ec2-3-135-202-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:02:18.394507 2026] [security2:error] [pid 4034031:tid 4034031] [client 3.135.202.169:50592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cruisingforsex.com"] [uri "/.git/config"] [unique_id "amb0al4UDOgXZl9xklWiTgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-27 05:12:59
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.dev | Evidence: www.crucerofluvial.com 3.13 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.dev | Evidence: www.crucerofluvial.com 3.135.202.169 - - [27/Jul/2026:07:12:23 +0200] \"GET /.env.dev HTTP/1.1\" 404 4815 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: AMAZON-02 | Country: US
show less
Port Scan
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 04:34:07
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack