๐ซ๐ท
Catalin Negru
2026-07-27 19:03:58
(11 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 12:29:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:29:16.658756 2026] [security2:error] [pid 3858502:tid 3858502] [client 3.78.216.164:47484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "revision.ws"] [uri "/.git/config"] [unique_id "amdPHABrIDKbV39PvIMiSgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:39:19
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:39:10.862436 2026] [security2:error] [pid 3545099:tid 3545099] [client 3.78.216.164:47984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "revgolf.five21.com"] [uri "/.git/config"] [unique_id "amcLHhbkNLGsjKhMdlxDXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-07-26 03:27:26
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 21:59:49
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 04:14:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:14:09.802212 2026] [security2:error] [pid 1012653:tid 1012653] [client 3.78.216.164:50708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "readyremotely.com"] [uri "/.git/config"] [unique_id "amQ4EWYuqiWuQnStBujgTAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lnklnx
2026-07-25 02:54:15
(3 days ago)
reader.lnklnx.com:443 3.78.216.164 - - [24/Jul/2026:21:54:13 -0500] "GET /.git/config HTTP/1.1" 302 ...
show more
reader.lnklnx.com:443 3.78.216.164 - - [24/Jul/2026:21:54:13 -0500] "GET /.git/config HTTP/1.1" 302 5410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-07-25 00:03:14
(3 days ago)
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 ( ...
show more
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.local HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.production HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.staging HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:33:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:33:17.526942 2026] [security2:error] [pid 3994923:tid 3994923] [client 3.78.216.164:35560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.daprototype.desertalfas.org"] [uri "/.git/config"] [unique_id "amOh3X3bQp-izgUqv-o4JwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:43:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:43:08.757981 2026] [security2:error] [pid 561844:tid 561844] [client 3.78.216.164:51996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dannyvanryswyk.dannyvanrijswijk.com"] [uri "/.git/config"] [unique_id "amOWHJ2DJ2OemK91bLfNGgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 13:47:52
(3 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 12:50:03
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 12:14:38
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 08:45:03
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 06:30:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:30:39.895814 2026] [security2:error] [pid 4098824:tid 4098824] [client 3.78.216.164:58630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.d2d.aarce.me"] [uri "/.git/config"] [unique_id "amMGj6TPgkL9qa9KKqmOsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack