Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=408; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=408; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:01:38
(1 month ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ซ๐ท
Octopuce
2026-07-24 12:18:55
(1 month ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:01:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:01:06.951642 2026] [security2:error] [pid 3618656:tid 3618656] [client 3.252.202.173:54464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zavijava.net"] [uri "/.git/config"] [unique_id "amNUAuLWoPt-LQtBsUk_cQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 09:08:10
(1 month ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ท๐บ
DZBOT
2026-07-24 07:38:48
(1 month ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-07-24 07:19:27
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 3.252.202.173 (IE/Ireland/ec2-3-252-202 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.252.202.173 (IE/Ireland/ec2-3-252-202-173.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-24 05:09:42
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:09:34.121752 2026] [security2:error] [pid 3771063:tid 3771063] [client 3.252.202.173:36476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zacharypowers.com"] [uri "/.git/config"] [unique_id "amLzjsEq_D3vclKrCDSXdAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
themrdogs
2026-07-24 04:39:28
(1 month ago)
$f2bV_matches
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:06:46
(2 months ago)
(mod_security) mod_security (id:240950) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.comp ...
show more
(mod_security) mod_security (id:240950) triggered by 3.252.202.173 (ec2-3-252-202-173.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:06:40.124018 2026] [security2:error] [pid 11018:tid 11018] [client 3.252.202.173:57990] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||zydecajun.radio.fm|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zydecajun.radio.fm"] [uri "/secure/QueryComponentRendererValue!Default.jspa"] [unique_id "aietcAvYWtdryG2v2uDMOQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack