๐บ๐ธ
TPI-Abuse
2026-07-24 00:23:49
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 20:23:43.016317 2026] [security2:error] [pid 17168:tid 17248] [client 3.81.94.197:59506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "btoelsalvador.com"] [uri "/.env"] [unique_id "amKwj4f4Wfp0CopoP5Ic7QAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-24 00:05:08
(40 minutes ago)
Too many Status 40X (21)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-23 22:01:54
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-22.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 22:00:36
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:00:30.970040 2026] [security2:error] [pid 4035682:tid 4035702] [client 3.81.94.197:55952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.wasula.com"] [uri "/.env"] [unique_id "amKO_mySRXQFNc6z1Bh-sAAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 14:47:08
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 3.81.94.197 (ec2-3-81-94-197.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 10:47:04.150513 2026] [security2:error] [pid 2113:tid 2113] [client 3.81.94.197:43824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balay.pamplonaserviciotecnico.com"] [uri "/.env"] [unique_id "amIpaEyXaCONKS9e4XOG_wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-07-23 05:15:12
(19 hours ago)
130 attacks on PHP URLs, password grabbing URLs, VC URLs, config grabbing URLs (type 2), env grabbin ...
show more
130 attacks on PHP URLs, password grabbing URLs, VC URLs, config grabbing URLs (type 2), env grabbing URLs, site downloads:
GET /phpmyadmin/ HTTP/1.1
GET /.vscode/sftp.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /config/config.json HTTP/1.1
GET /supabase/.env HTTP/1.1
GET /src.zip HTTP/1.1
show less
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-07-23 04:33:43
(20 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-07-22 22:07:26
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-22 21:59:09
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-22
Web App Attack
SSH
Hacking
๐ณ๐ฑ
ipoac.nl
2026-07-22 21:03:47
(1 day ago)
-:443 3.81.94.197 - - [22/Jul/2026:23:03:46 +0200] - "GET /settings/production.py HTTP/2.0" 404 2115 ...
show more
-:443 3.81.94.197 - - [22/Jul/2026:23:03:46 +0200] - "GET /settings/production.py HTTP/2.0" 404 2115 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Bad Web Bot
๐บ๐ธ
Rbot
2026-07-22 19:22:00
(1 day ago)
/mysql/, /netlify.toml, t/pma/,phpmyadmin/
Web App Attack
Hacking
๐บ๐ธ
Rbot
2026-07-22 19:00:00
(1 day ago)
40 attacks to gain access including /application.yaml, ?rest_route=%2Fbatch%2Fv1
Web App Attack
Hacking
๐ซ๐ท
Octopuce
2026-07-22 16:34:59
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env .. ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /api/.env /backend/.env /admin/.env ...
show less
Web App Attack
๐ฎ๐น
Inartis
2026-07-22 14:17:00
(1 day ago)
3.81.94.197 - - [22/Jul/2026:15:16:58 +0200] "GET /.env.development HTTP/1.1" 503 23881 "-" "Mozilla ...
show more
3.81.94.197 - - [22/Jul/2026:15:16:58 +0200] "GET /.env.development HTTP/1.1" 503 23881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
3.81.94.197 - - [22/Jul/2026:15:16:59 +0200] "GET /.env.staging HTTP/1.1" 503 23881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
3.81.94.197 - - [22/Jul/2026:16:16:59 +0200] "GET /.git/config HTTP/1.1" 503 23881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 13:18:02
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack