๐จ๐ญ
Elysium Security
2026-07-17 08:41:17
(1 week ago)
Mass scanning for Web CVE
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-17 08:19:05
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
electra
2026-07-17 00:57:21
(1 week ago)
Attempted to access path /.git/config (GET request)
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 00:07:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 20:07:28.148540 2026] [security2:error] [pid 7613:tid 7674] [client 3.36.88.10:36240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.earthtravel.net"] [uri "/.git/config"] [unique_id "allyQIkrzV-ifcORUNswLgAAAZg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 23:20:59
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:949110) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 19:20:54.795536 2026] [security2:error] [pid 26943:tid 26943] [client 3.36.88.10:52686] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.dynamictesting.net"] [uri "/.git/config"] [unique_id "allnVu9kIrQfESbnhm7gVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-16 22:00:14
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-15.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-16 17:26:55
(1 week ago)
(caddyscan) Scanner path probe from 3.36.88.10 (KR/South Korea/ec2-3-36-88-10.ap-northeast-2.compute ...
show more
(caddyscan) Scanner path probe from 3.36.88.10 (KR/South Korea/ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.36.88.10 - - [16/Jul/2026:17:26:50 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.36.88.10 - - [16/Jul/2026:17:26:51 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.36.88.10 - - [16/Jul/2026:17:26:51 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.36.88.10 - - [16/Jul/2026:17:26:51 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.36.88.10 - - [16/Jul/2026:17:26:51 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐ณ๐ฑ
Mangelot Hosting
2026-07-16 10:06:29
(1 week ago)
(modsecurity) srv102 ModSecurity 3.36.88.10 (KR/South Korea/ec2-3-36-88-10.ap-northeast-2.compute.am ...
show more
(modsecurity) srv102 ModSecurity 3.36.88.10 (KR/South Korea/ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 08:29:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 04:29:36.090718 2026] [security2:error] [pid 23103:tid 23103] [client 3.36.88.10:44674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.desertshadowsrv.org"] [uri "/.git/config"] [unique_id "aliWcCnO6vfgR5rEOhg5EgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 06:32:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 02:32:35.670987 2026] [security2:error] [pid 17715:tid 17715] [client 3.36.88.10:54412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.delidalga.com"] [uri "/.git/config"] [unique_id "alh7A_YfOF4WStyqssGWrwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-16 06:21:21
(1 week ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-16 06:12:55
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 04:17:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 00:17:51.089815 2026] [security2:error] [pid 12476:tid 12476] [client 3.36.88.10:36240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dddrapery.com"] [uri "/.git/config"] [unique_id "alhbb-1L3_Y8z39lOik3TwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 03:00:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.36.88.10 (ec2-3-36-88-10.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 23:00:00.900154 2026] [security2:error] [pid 25712:tid 25712] [client 3.36.88.10:53144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davidmei.com"] [uri "/.git/config"] [unique_id "alhJMODxhvF-MnyAld9bDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-15 22:01:45
(1 week ago)
Auto-ban: >3000 req/min op 2026-07-15
Web App Attack
SSH
Hacking