๐บ๐ธ
TPI-Abuse
2026-07-27 22:14:13
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:14:08.513325 2026] [security2:error] [pid 840205:tid 840205] [client 3.249.50.177:43516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desarrollosdecolima.com"] [uri "/.git/config"] [unique_id "amfYMPxnCipoDqfaadkzsgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:01:42
(16 hours ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
big-cloud.nl
2026-07-27 20:43:00
(18 hours ago)
Try to access /.git/config
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 19:30:30
(19 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
Anonymous
2026-07-27 17:14:08
(21 hours ago)
Bot / scanning and/or hacking attempts: POST / HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.dev HT ...
show more
Bot / scanning and/or hacking attempts: POST / HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.save HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-07-27 16:55:41
(22 hours ago)
3.249.50.177 (IE/Ireland/ec2-3-249-50-177.eu-west-1.compute.amazonaws.com), more than 7 Apache 403 h ...
show more
3.249.50.177 (IE/Ireland/ec2-3-249-50-177.eu-west-1.compute.amazonaws.com), more than 7 Apache 403 hits
show less
Hacking
๐ซ๐ท
Hippoline
2026-07-27 15:44:39
(23 hours ago)
[Mon Jul 27 17:44:29.787820 2026] [authz_core:error] [pid 8128] [client 3.249.50.177:34574] AH01630: ...
show more
[Mon Jul 27 17:44:29.787820 2026] [authz_core:error] [pid 8128] [client 3.249.50.177:34574] AH01630: client denied by server configuration: /var/www/deppefest.lu/web/cakephp
[Mon Jul 27 17:44:38.630026 2026] [authz_core:error] [pid 7347] [client 3.249.50.177:57828] AH01630: client denied by server configuration: /var/www/deppefest.lu/web/phpinfo.php
[Mon Jul 27 17:44:38.673145 2026] [authz_core:error] [pid 7347] [client 3.249.50.177:57828] AH01630: client denied by server configuration: /var/www/deppefest.lu/web/info.php
[Mon Jul 27 17:44:38.736026 2026] [authz_core:error] [pid 7347] [client 3.249.50.177:57828] AH01630: client denied by server configuration: /var/www/deppefest.lu/web/php.php
[Mon Jul 27 17:44:38.772535 2026] [authz_core:error] [pid 7347] [client 3.249.50.177:57828] AH01630: client denied by server configuration: /var/www/deppefest.lu/web/i.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:48:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:48:05.032080 2026] [security2:error] [pid 3748046:tid 3748046] [client 3.249.50.177:59874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deploy6tharmy.com.mininoarg.com"] [uri "/.git/config"] [unique_id "amdvpTVLBXLe5QXJ6gMPgQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:29:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:29:47.673970 2026] [security2:error] [pid 1568870:tid 1568870] [client 3.249.50.177:46472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deoudewindpomp.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "amdPO2SZObR0Ni-6IKschwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 12:16:48
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-27 11:53:28
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-27 11:32:53
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 11:23:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:23:50.931848 2026] [security2:error] [pid 2318221:tid 2318371] [client 3.249.50.177:51384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.denverdermatologist.aafm.us"] [uri "/.git/config"] [unique_id "amc_xoflpnRwa9G8FTuZhAAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:00:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.249.50.177 (ec2-3-249-50-177.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:00:28.406663 2026] [security2:error] [pid 258652:tid 258652] [client 3.249.50.177:49152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.denroydannursery.edgeimprov.com"] [uri "/.git/config"] [unique_id "amcCDN3RypSzt9lXHK4sMwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-07-27 06:05:01
(1 day ago)
~ suspicious post ~
Hacking
Web App Attack