π³π±
homeshowdomain.nl
2026-08-23 22:03:43
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-22.
show less
Web App Attack
SSH
Hacking
ππΊ
miszterx.hu
2026-08-23 10:43:46
(3 days ago)
XORP (haproxy): 222x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_i ...
show more
XORP (haproxy): 222x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
ππΊ
miszterx.hu
2026-08-22 18:57:56
(4 days ago)
XORP (haproxy): 11x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 11x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
π«π·
dynamix
2026-08-22 18:41:13
(4 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 07:38:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.221.49.176 (ec2-34-221-49-176.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.49.176 (ec2-34-221-49-176.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:38:47.916570 2026] [security2:error] [pid 14157:tid 14157] [client 34.221.49.176:50848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingwelding.com"] [uri "/.git/config"] [unique_id "aolSB2FC8UZC9LPWS5gYgQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 06:57:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.221.49.176 (ec2-34-221-49-176.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.221.49.176 (ec2-34-221-49-176.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:57:42.831440 2026] [security2:error] [pid 28490:tid 28490] [client 34.221.49.176:53150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinggraceministries.net"] [uri "/.git/config"] [unique_id "aolIZpx-sEXfvSxRQ3Yi6wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-22 05:46:27
(4 days ago)
Excessive 404/403 errors
Brute-Force
π΅π«
www.gregorymariani.com
2026-08-22 04:15:35
(4 days ago)
34.221.49.176 - - [22/Aug/2026:04:15:28 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 ...
show more
34.221.49.176 - - [22/Aug/2026:04:15:28 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 547 0.009 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.009 404 444067814f427969f709f014f84aaa72
34.221.49.176 - - [22/Aug/2026:04:15:29 +0000] "GET /.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 540 0.008 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.007 404 a8bfcd5be5853081b261374f0bf406dc
34.221.49.176 - - [22/Aug/2026:04:15:30 +0000] "GET /.env.local HTTP/1.1" 404 179 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 546 0.021 [default-shop-oscar-amartyne-8080] [] 10.244.41.147:8080 179 0.021 404 18a354aaae3efeb00638c533dab434f1
34.221.49.176 - - [22/Aug/2026:04:15:30 +0000
...
show less
Web App Attack
π«π·
Octopuce
2026-08-22 01:52:40
(4 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
π§π·
dominioz
2026-08-21 23:44:15
(4 days ago)
2026-08-21 23:43:23 GET /.git/config - - 34.221.49.176 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS ...
show more
2026-08-21 23:43:23 GET /.git/config - - 34.221.49.176 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 558
2026-08-21 23:43:24 GET /err/ 404;https://amanda.jor.br:443/.git/config - 34.221.49.176 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 403 226
2026-08-21 23:43:24 GET /.env - - 34.221.49.176 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 544
2026-08-21 23:43:24 GET /err/ 404;https://amanda.jor.br:443/.env - 34.221.49.176 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 403 226
...
show less
Web App Attack
π«π·
masterguru
2026-08-21 11:05:21
(5 days ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking