๐ซ๐ท
COMAITE
2026-09-16 20:13:17
(3 weeks ago)
XSS (Cross Site Scripting) attempt from 3.254.87.114.
Web App Attack
๐ซ๐ฎ
S S
2026-08-03 12:46:15
(2 months ago)
Automated vulnerability scanning against our ad-serving web servers: 210 HTTP 4xx probes across 3 pu ...
show more
Automated vulnerability scanning against our ad-serving web servers: 210 HTTP 4xx probes across 3 public web front-ends between 2026-07-27 and 2026-08-03 (UTC). Sample probed paths: /.env.backup, /.env.old, /.env.production, /.env.remote, /.env1, /api/.env. Non-existent paths, no legitimate traffic from this IP.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 months ago)
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
Anonymous
2026-07-27 18:49:12
(2 months ago)
3.254.87.114 - - [27/Jul/2026:20:49:12 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ( ...
show more
3.254.87.114 - - [27/Jul/2026:20:49:12 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:39:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:39:04.501075 2026] [security2:error] [pid 3473659:tid 3473659] [client 3.254.87.114:53804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtrl.com"] [uri "/.git/config"] [unique_id "amd7mL6TE-AZRI3HcoWfJgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-07-27 15:23:33
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 3.254.87.114 (IE/Ireland/ec2-3-254-87-114.eu-we ...
show more
(mod_security) mod_security (id:949110) triggered by 3.254.87.114 (IE/Ireland/ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 15:05:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:05:22.214865 2026] [security2:error] [pid 21672:tid 21672] [client 3.254.87.114:49118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtremeautodetailing.com"] [uri "/.git/config"] [unique_id "amdzssdAZ9WI4qbyposR1AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 13:29:48
(2 months ago)
(caddyscan) Scanner path probe from 3.254.87.114 (IE/Ireland/ec2-3-254-87-114.eu-west-1.compute.amaz ...
show more
(caddyscan) Scanner path probe from 3.254.87.114 (IE/Ireland/ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.254.87.114 - - [27/Jul/2026:13:29:47 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.254.87.114 - - [27/Jul/2026:13:29:47 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.254.87.114 - - [27/Jul/2026:13:29:47 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.254.87.114 - - [27/Jul/2026:13:29:47 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.254.87.114 - - [27/Jul/2026:13:29:47 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 12:00:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:00:35.491356 2026] [security2:error] [pid 1332140:tid 1332140] [client 3.254.87.114:51474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xtcdesigns.com"] [uri "/.git/config"] [unique_id "amdIY4BbRBBw5RJECIfm9AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-27 05:35:32
(2 months ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:04:17
(2 months ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-07-24 11:33:58
(2 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 09:20:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 3.254.87.114 (ec2-3-254-87-114.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:20:44.591696 2026] [security2:error] [pid 3607611:tid 3607611] [client 3.254.87.114:60022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.urie.to.daveewalker.bz"] [uri "/.git/config"] [unique_id "amMubA186yZJd5VWxej7GQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 09:10:03
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 06:37:06
(2 months ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack