๐ซ๐ท
Catalin Negru
2026-07-26 03:27:26
(22 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 21:59:49
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 04:14:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:14:09.802212 2026] [security2:error] [pid 1012653:tid 1012653] [client 3.78.216.164:50708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "readyremotely.com"] [uri "/.git/config"] [unique_id "amQ4EWYuqiWuQnStBujgTAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lnklnx
2026-07-25 02:54:15
(1 day ago)
reader.lnklnx.com:443 3.78.216.164 - - [24/Jul/2026:21:54:13 -0500] "GET /.git/config HTTP/1.1" 302 ...
show more
reader.lnklnx.com:443 3.78.216.164 - - [24/Jul/2026:21:54:13 -0500] "GET /.git/config HTTP/1.1" 302 5410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-07-25 00:03:14
(2 days ago)
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 ( ...
show more
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.local HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.production HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.env.staging HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.78.216.164 - - [25/Jul/2026:02:03:11 +0200] "GET /.
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:33:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:33:17.526942 2026] [security2:error] [pid 3994923:tid 3994923] [client 3.78.216.164:35560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.daprototype.desertalfas.org"] [uri "/.git/config"] [unique_id "amOh3X3bQp-izgUqv-o4JwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:43:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:43:08.757981 2026] [security2:error] [pid 561844:tid 561844] [client 3.78.216.164:51996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dannyvanryswyk.dannyvanrijswijk.com"] [uri "/.git/config"] [unique_id "amOWHJ2DJ2OemK91bLfNGgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 13:47:52
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 12:50:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 12:14:38
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 08:45:03
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 06:30:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:30:39.895814 2026] [security2:error] [pid 4098824:tid 4098824] [client 3.78.216.164:58630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.d2d.aarce.me"] [uri "/.git/config"] [unique_id "amMGj6TPgkL9qa9KKqmOsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 04:26:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:26:21.286502 2026] [security2:error] [pid 3374935:tid 3374935] [client 3.78.216.164:38986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cyprus-boat-registration.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "amLpbazkUnp4TX6SLYT-5gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 04:07:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:07:51.615606 2026] [security2:error] [pid 347640:tid 347662] [client 3.78.216.164:33138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cynosurelandscapers.cynosureinternetservices.com"] [uri "/.git/config"] [unique_id "amLlF8Kb2QsP4Rkrht_JnwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:37:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.78.216.164 (ec2-3-78-216-164.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:37:47.129140 2026] [security2:error] [pid 3785009:tid 3785009] [client 3.78.216.164:46796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cydab.com.greighhouse.com"] [uri "/.git/config"] [unique_id "amLeCz-kZay0eb4yYKKCGAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack