🇫🇷
COMAITE
2026-09-07 10:15:44
(1 week ago)
Suspicious URL access.
Web App Attack
🇩🇪
webanyone
2026-09-07 08:47:19
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇫🇷
thilo
2026-09-07 06:38:57
(1 week ago)
Probe for vulnerabilities. Path attempted: /.env.local
Web App Attack
🇫🇷
dynamix
2026-09-06 23:51:54
(1 week ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:47:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:47:21.073907 2026] [security2:error] [pid 28336:tid 28336] [client 3.96.157.130:48794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clipper1970.com"] [uri "/.git/config"] [unique_id "ap3teVOjZ_Y38TfEO21qjQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 22:38:11
(1 week ago)
🔥 VERY AGGRESSIVE SCANNER probed over 500 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:28:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:28:33.713242 2026] [security2:error] [pid 4464:tid 4464] [client 3.96.157.130:33728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clip24.net"] [uri "/.git/config"] [unique_id "ap3bAZT54P5KLL5xrA6pvgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:22:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:22:24.405406 2026] [security2:error] [pid 24614:tid 24614] [client 3.96.157.130:37942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clintcurrin.com"] [uri "/.git/config"] [unique_id "ap3LgFbhPdOwXApE8TxkrAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 19:43:12
(1 week ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:02:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:02:16.309059 2026] [security2:error] [pid 3806:tid 3806] [client 3.96.157.130:39046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.posteios.com"] [uri "/.git/config"] [unique_id "ap1kWOnugIRv2rZnyLGrEwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
dominioz
2026-09-06 12:02:56
(1 week ago)
2026-09-06 12:02:00 GET /.git/config - - 3.96.157.130 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+Apple ...
show more
2026-09-06 12:02:00 GET /.git/config - - 3.96.157.130 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 586
2026-09-06 12:02:00 GET /err/ 404;https://clinicadurand.com.br:443/.git/config - 3.96.157.130 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 403 226
2026-09-06 12:02:00 GET /.env - - 3.96.157.130 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 572
2026-09-06 12:02:01 GET /err/ 404;https://clinicadurand.com.br:443/.env - 3.96.157.130 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 403 226
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 11:00:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 3.96.157.130 (ec2-3-96-157-130.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 07:00:46.320102 2026] [security2:error] [pid 2655:tid 2655] [client 3.96.157.130:35684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clinicadentaldiaz.aticom.es"] [uri "/.git/config"] [unique_id "ap1H3pfBAVgxminXwaXpAQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 09:39:44
(1 week ago)
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux ...
show more
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
3.96.157.130 - - [06/Sep/2026:11:39:44 +0200] "GET /.env.local HTTP/1.1" 403 183 "-" "M
...
show less
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 04:28:58
(1 week ago)
cloudlinux2 fail2ban: 2026-09-06 06:25:13,320 fail2ban.filter [2048]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 06:25:13,320 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.236.38.77 - 2026-09-06 06:25:13cloudlinux2 fail2ban: 2026-09-06 06:25:13,828 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.236.38.77 - 2026-09-06 06:25:13cloudlinux2 fail2ban: 2026-09-06 06:25:13,923 fail2ban.filter [2048]: INFO [recidive] Found 35.236.38.77 - 2026-09-06 06:25:13cloudlinux2 fail2ban: 2026-09-06 06:25:13,657 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.236.38.77 - 2026-09-06 06:25:13cloudlinux2 fail2ban: 2026-09-06 06:25:13,491 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.236.38.77 - 2026-09-06 06:25:13cloudlinux2 fail2ban: 2026-09-06 06:25:13,918 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Ban 35.236.38.77cloudlinux2 fail2ban: 2026-09-06 06:25:12,856 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.236.38.77 - 2026-09-06 06:25:12cloudlinux2 fail2ban: 2026-09-06 06
show less
Brute-Force
🇦🇺
AWW-Admin
2026-09-05 21:42:07
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 3.96.157.130 (CA/Canada/ec2-3-96-157-13 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.96.157.130 (CA/Canada/ec2-3-96-157-130.ca-central-1.compute.amazonaws.com)
show less
SQL Injection