๐บ๐ธ
gumbysoft
2026-07-25 03:19:43
(5 hours ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-25 02:55:32
(6 hours ago)
32.236.189.96 - - [24/Jul/2026:22:55:24 -0400] "GET /.git/config HTTP/1.0" 404 5764 "-" "Mozilla/5.0 ...
show more
32.236.189.96 - - [24/Jul/2026:22:55:24 -0400] "GET /.git/config HTTP/1.0" 404 5764 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
32.236.189.96 - - [24/Jul/2026:22:55:24 -0400] "GET /.env HTTP/1.0" 500 5330 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
32.236.189.96 - - [24/Jul/2026:22:55:31 -0400] "GET /app/.env HTTP/1.0" 404 5764 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-24 22:45:40
(10 hours ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 20:28:38
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 16:28:32.646171 2026] [security2:error] [pid 3318736:tid 3318736] [client 32.236.189.96:44200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.darrow.biz.loudenlow.com"] [uri "/.git/config"] [unique_id "amPK8LiUB-ACgsd6ImbvAwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
900cm
2026-07-24 18:02:55
(15 hours ago)
[Fri Jul 24 20:02:54.302180 2026] [access_compat:error] [pid 429722:tid 429722] [client 32.236.189.9 ...
show more
[Fri Jul 24 20:02:54.302180 2026] [access_compat:error] [pid 429722:tid 429722] [client 32.236.189.96:51008] AH01797: client denied by server configuration: /var/www/darkintruder/.git
[Fri Jul 24 20:02:54.838606 2026] [access_compat:error] [pid 429722:tid 429722] [client 32.236.189.96:51008] AH01797: client denied by server configuration: /var/www/darkintruder/.env
[Fri Jul 24 20:02:55.105528 2026] [access_compat:error] [pid 429722:tid 429722] [client 32.236.189.96:51008] AH01797: client denied by server configuration: /var/www/darkintruder/.env.local
...
show less
Port Scan
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-24 16:20:31
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:20:25.980424 2026] [security2:error] [pid 4147197:tid 4147197] [client 32.236.189.96:55672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.daretodreamproductions.homehealth101.com"] [uri "/.git/config"] [unique_id "amOQyXGbO507oEcC_ZQi2AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 14:40:04
(18 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:35:38
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:35:33.377452 2026] [security2:error] [pid 3817238:tid 3817238] [client 32.236.189.96:38788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.daprototype.desertalfas.org"] [uri "/.git/config"] [unique_id "amN4NV9kO6gcFmVQbhXFpAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:53:56
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:53:52.007144 2026] [security2:error] [pid 4035281:tid 4035281] [client 32.236.189.96:43590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danzantesdehuesca.com.disnet-m.com"] [uri "/.git/config"] [unique_id "amNgYObUXyy-FqzuZrQjqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:37:21
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 32.236.189.96 (ec2-32-236-189-96.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:37:14.228973 2026] [security2:error] [pid 89189:tid 89189] [client 32.236.189.96:44518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dannyvanryswyk.dannyvanrijswijk.com"] [uri "/.git/config"] [unique_id "amNAWjdE1Di_olSqzA_aFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack