Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=203; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=203; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [203 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:02:09
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐ฌ๐ง
Oakley
2026-07-27 15:13:59
(3 days ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 13:12:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:12:00.434153 2026] [security2:error] [pid 3871753:tid 3871753] [client 3.254.148.19:51500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "menafert.com"] [uri "/.git/config"] [unique_id "amdZIIeIChjYCtCpGthaBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:30:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:30:18.206616 2026] [security2:error] [pid 22168:tid 22168] [client 3.254.148.19:35272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memphislimousines.com"] [uri "/.git/config"] [unique_id "amdPWnSwQjHJeeYp90fBLwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sigurg
2026-07-27 12:11:05
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 11:09:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:09:03.522933 2026] [security2:error] [pid 1275723:tid 1275723] [client 3.254.148.19:48670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memoriesmusic.net.controvac.com"] [uri "/.git/config"] [unique_id "amc8TyGfvrPKmJ4caI0fhwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-27 10:00:05
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 06:56:52
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-07-27 06:50:02
(3 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:31:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.148.19 (ec2-3-254-148-19.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:31:38.085068 2026] [security2:error] [pid 21966:tid 21966] [client 3.254.148.19:53716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "members.oxfordgliding.com"] [uri "/.git/config"] [unique_id "amb7SoeuZob8WpO21QHC6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-26 07:05:03
(4 days ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-26 06:17:29
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-26 04:17:09
(4 days ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
nekopavel
2026-07-26 03:28:17
(4 days ago)
3.254.148.19 - - [26/Jul/2026:05:28:15 +0200]"GET /.git/config HTTP/1.1" 404 50890"-" mishashto.com ...
show more
3.254.148.19 - - [26/Jul/2026:05:28:15 +0200]"GET /.git/config HTTP/1.1" 404 50890"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.008" "0.000""Dublin" "IE"
3.254.148.19 - - [26/Jul/2026:05:28:15 +0200]"GET /.env HTTP/1.1" 404 50885"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.004" "0.000""Dublin" "IE"
3.254.148.19 - - [26/Jul/2026:05:28:15 +0200]"GET /.env.local HTTP/1.1" 404 50890"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.004" "0.000""Dublin" "IE"
...
show less
Hacking
Bad Web Bot
Web App Attack