Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=832; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=832; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-27 11:56:24
(3 days ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-27 08:05:10
(3 days ago)
Too many Status 50X (225)
Scanning/Probing (173)
Request Overload (225)
Brute-Force
Web App Attack
๐บ๐ธ
OceanTreasure
2026-07-27 05:27:38
(3 days ago)
tcp/443; WordPress admin access attempt: "GET /wp-admin/phpinfo.php" @ 2026-07-27T05:24:00Z [proxy]
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:05:45
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 16:00:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:00:46.013006 2026] [security2:error] [pid 378685:tid 378685] [client 34.242.160.31:59370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.campnecon.neconebooks.com"] [uri "/.git/config"] [unique_id "amOMLnet3Y_yze5DCqmUXQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:31:34
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:31:29.122356 2026] [security2:error] [pid 12508:tid 12508] [client 34.242.160.31:43040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.campconcerto.com.accordionclub.org"] [uri "/.git/config"] [unique_id "amOFUfAtUb-iqRTUEvbXKwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:39:00
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:38:55.716494 2026] [security2:error] [pid 4159526:tid 4159526] [client 34.242.160.31:45246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.camerongunsmith.com.worldchat.global"] [uri "/.git/config"] [unique_id "amN4_wjsvkZLTxjipumX7wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:28:09
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:28:04.623373 2026] [security2:error] [pid 2711859:tid 2711859] [client 34.242.160.31:52354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calvet1937.marcelacalvet.com"] [uri "/.git/config"] [unique_id "amNoZAZmFXhJEz04ETHm7QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:26:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:25:56.766941 2026] [security2:error] [pid 135024:tid 135024] [client 34.242.160.31:43832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.californiabrokers.californiaappraisers.net"] [uri "/.git/config"] [unique_id "amNLxNfHS20S9c3XpPNaRgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:40:11
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:40:07.348205 2026] [security2:error] [pid 697832:tid 697832] [client 34.242.160.31:39174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.calebdavison.jsdavison.com"] [uri "/.git/config"] [unique_id "amNBB8FbTlXaOs19uVWCggAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:07:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.242.160.31 (ec2-34-242-160-31.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:07:03.015472 2026] [security2:error] [pid 752456:tid 752479] [client 34.242.160.31:37516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cahnlist.wwwhst.com"] [uri "/.git/config"] [unique_id "amMrN1EPOvqW5JFY42WzuAAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 08:50:35
(6 days ago)
34.242.160.31 - - [24/Jul/2026:03:50:31 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 ( ...
show more
34.242.160.31 - - [24/Jul/2026:03:50:31 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 208.109.0.40
34.242.160.31 - - [24/Jul/2026:03:50:31 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 208.109.0.40
34.242.160.31 - - [24/Jul/2026:03:50:32 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 208.109.0.40
34.242.160.31 - - [24/Jul/2026:03:50:32 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 208.109.0.40
34.242.160.31 - - [24/Jul/2026:03:50:32 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWe
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 08:39:47
(6 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-07-24 07:45:27
(6 days ago)
Excessive 404/403 errors
Brute-Force