๐บ๐ธ
TPI-Abuse
2026-07-28 05:13:50
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210730) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:13:45.301270 2026] [security2:error] [pid 396856:tid 396856] [client 3.252.85.81:32850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bitcoincasting.usaangelinvestors.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bitcoincasting.usaangelinvestors.com"] [uri "/.env.bak"] [unique_id "amg6ibrUFBD_8gXl82roQQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-28 03:06:00
(22 hours ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
๐ซ๐ท
masterguru
2026-07-27 22:17:08
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:01:05
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-07-27 21:59:16
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 16:46:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:46:00.166931 2026] [security2:error] [pid 528179:tid 528179] [client 3.252.85.81:59044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.business.lsd36.com"] [uri "/.git/config"] [unique_id "ameLSJLWnxK6lz3JL4YRdQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:44:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:44:42.440384 2026] [security2:error] [pid 3682277:tid 3682277] [client 3.252.85.81:42750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burnshieldmena.thechoiceint.com"] [uri "/.git/config"] [unique_id "amdSulzUgtUfusRKKW7mMQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:29:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:29:00.524460 2026] [security2:error] [pid 244742:tid 244742] [client 3.252.85.81:39068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burningdownthevillger.com.tremulant.com"] [uri "/.git/config"] [unique_id "amdPDCWUna9eBKUgEDGbawAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-27 12:08:21
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:40:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:40:44.218235 2026] [security2:error] [pid 99640:tid 99640] [client 3.252.85.81:59832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.burke698.org.nilestree.com"] [uri "/.git/config"] [unique_id "amdDvBo6u0cw2ZLhTaIt2wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-27 10:43:31
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
Anonymous
2026-07-27 10:39:05
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.env.dist HTTP/1.1, GET /app/.env HTTP/1.1, GET /web/.e ...
show more
Bot / scanning and/or hacking attempts: GET /.env.dist HTTP/1.1, GET /app/.env HTTP/1.1, GET /web/.env HTTP/1.1, GET /apps/.env HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env1 HTTP/1.1, GET /admin/.env HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.yml HTTP/1.1, GET /site/.env HTTP/1.1, GET /.env_copy HTTP/1.1, GET /public/.env HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.json HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-07-27 01:20:54
(2 days ago)
Scanning for web/db/file exploits on www.dutchtableau.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-27 01:04:21
(2 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 05:28:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.252.85.81 (ec2-3-252-85-81.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 01:28:44.636813 2026] [security2:error] [pid 4154917:tid 4154978] [client 3.252.85.81:59316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.florida-plastic-surgery.aafm.us"] [uri "/.git/config"] [unique_id "amWbDG9MdK2i4-dcvS2lnQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack