Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=1478; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1478; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 17:04:49
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:04:45.201522 2026] [security2:error] [pid 285759:tid 285759] [client 3.254.153.45:53360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perthdps.com"] [uri "/.git/config"] [unique_id "amePrUtuvw7zOMaKSOa7uAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-07-27 15:34:17
(1 month ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-07-27 12:31:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:31:22.542127 2026] [security2:error] [pid 3414034:tid 3414034] [client 3.254.153.45:50644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "personal-sportswear.com"] [uri "/.git/config"] [unique_id "amdPmlp7fggwFsrd4grixgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-07-27 11:49:54
(1 month ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
zwebvigil
2026-07-27 10:50:49
(1 month ago)
3.254.153.45 [27/Jul/2026:03:50:49 -0700] "POST / HTTP/1.1" 405 31 "-" port=41350 "Mozilla/5.0 (X11 ...
show more
3.254.153.45 [27/Jul/2026:03:50:49 -0700] "POST / HTTP/1.1" 405 31 "-" port=41350 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "<host>" 4501
3.254.153.45 [27/Jul/2026:03:50:49 -0700] "POST / HTTP/1.1" 405 31 "-" port=41350 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "<host>" 3095
3.254.153.45 [27/Jul/2026:03:50:49 -0700] "POST / HTTP/1.1" 405 31 "-" port=41350 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "<host>" 3081
3.254.153.45 [27/Jul/2026:03:50:49 -0700] "POST / HTTP/1.1" 405 31 "-" port=41350 "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "
show less
Web App Attack
Anonymous
2026-07-27 08:18:55
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 3.254.153.45 (IE/Ireland/ec2-3-254-153- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.254.153.45 (IE/Ireland/ec2-3-254-153-45.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
🇳🇱
e.fierstra
2026-07-27 06:58:40
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 05:34:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:34:00.809569 2026] [security2:error] [pid 89865:tid 89865] [client 3.254.153.45:49134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perkowski.net"] [uri "/.git/config"] [unique_id "ambtyA-XpzFnEK5MUCormgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 04:23:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:23:35.247731 2026] [security2:error] [pid 4128359:tid 4128359] [client 3.254.153.45:40556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "periodthreads.com"] [uri "/.git/config"] [unique_id "ambdRwhvd_Gol5l7u6LPqgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-07-26 06:16:42
(1 month ago)
Excessive multi-domain requests
Brute-Force
🇫🇷
masterguru
2026-07-26 03:29:31
(1 month ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-26 03:01:25
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.153.45 (ec2-3-254-153-45.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 23:01:18.684653 2026] [security2:error] [pid 7553:tid 7553] [client 3.254.153.45:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixacast.com"] [uri "/.git/config"] [unique_id "amV4fhCbRKyn7r0bTxKrtgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hary74656
2026-07-26 02:49:38
(1 month ago)
[Sun Jul 26 04:49:30.004582 2026] [security2:error] [pid 234903:tid 234986] [client 3.254.153.45:541 ...
show more
[Sun Jul 26 04:49:30.004582 2026] [security2:error] [pid 234903:tid 234986] [client 3.254.153.45:54126] [client 3.254.153.45] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "attac
...
show less
Web App Attack
🇬🇧
consul.to
2026-07-26 02:07:44
(1 month ago)
Web attack/malicious scanning detected
Web App Attack