Anonymous
2026-07-29 07:00:00
(6 hours ago)
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ฆ๐บ
clapper
2026-07-27 06:38:44
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 3.71.36.205 (DE/Germany/ec2-3-71-36-205.eu-cent ...
show more
(mod_security) mod_security (id:949110) triggered by 3.71.36.205 (DE/Germany/ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 5 in the last 600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 06:32:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:32:01.616905 2026] [security2:error] [pid 3256:tid 3256] [client 3.71.36.205:33386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.nutandboltguy.com"] [uri "/.git/config"] [unique_id "amb7YUxQwLGGFPqcp07MiAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:04:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:04:44.050234 2026] [security2:error] [pid 3499881:tid 3499881] [client 3.71.36.205:37724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.itimetable21.com"] [uri "/.git/config"] [unique_id "amb0_L8RoEoBN2Z97gOsYQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-07-27 05:51:13
(2 days ago)
[MonJul2707:51:07.8888042026][security2:error][pid2572232:tid2572261][client3.71.36.205:0]ModSecurit ...
show more
[MonJul2707:51:07.8888042026][security2:error][pid2572232:tid2572261][client3.71.36.205:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ipv6.gmint.ch\"][uri\"/.git/config\"][unique_id\"ambxy7Mm3elKswJoKfA0yQAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:48:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:48:45.914162 2026] [security2:error] [pid 2924454:tid 2924454] [client 3.71.36.205:50532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.feaverslane.com"] [uri "/.git/config"] [unique_id "ambxPamP8cy9vCdN710lvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Matthew Ping
2026-07-27 05:45:01
(2 days ago)
ModSecurity rule 949110 triggered on cumberland. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 05:32:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:32:37.861332 2026] [security2:error] [pid 4027966:tid 4027966] [client 3.71.36.205:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.c2cservices.com"] [uri "/.git/config"] [unique_id "ambtdaxzOmfV1XDlA10y7gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-27 05:15:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:06:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:06:33.933150 2026] [security2:error] [pid 3365497:tid 3365497] [client 3.71.36.205:56006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.advantstudio.com"] [uri "/.git/config"] [unique_id "ambnWbUECuOgQoJv9fNcRwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
myip.foo
2026-07-27 04:58:15
(2 days ago)
[myip.foo] 3.71.36.205 - - [27/Jul/2026:04:58:14 +0000] "GET /.git/config HTTP/1.1" 404 150 "-" "Moz ...
show more
[myip.foo] 3.71.36.205 - - [27/Jul/2026:04:58:14 +0000] "GET /.git/config HTTP/1.1" 404 150 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 04:53:54
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:03:08
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:00:28
(4 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 08:31:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compu ...
show more
(mod_security) mod_security (id:210492) triggered by 3.71.36.205 (ec2-3-71-36-205.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:31:10.720072 2026] [security2:error] [pid 3617569:tid 3617569] [client 3.71.36.205:34866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flightsoffancyfilms.com"] [uri "/.git/config"] [unique_id "amMizsqYbdB6V_MbyZ-krwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack