Anonymous
2026-07-29 07:00:00
(37 minutes ago)
Apache probe; attempts=1279; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1279; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 04:03:50
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /.env.production /.env.staging /.env.de ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /.env.production /.env.staging /.env.development /.env.test /.env.remote /.env.bak ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 00:20:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 20:20:37.352367 2026] [security2:error] [pid 3539120:tid 3539120] [client 34.245.21.134:55464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hdeco.com"] [uri "/.git/config"] [unique_id "amakVWXk0TfeE3_j3waXqwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-26 23:37:42
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-26 23:04:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 19:04:20.890865 2026] [security2:error] [pid 2570126:tid 2570126] [client 34.245.21.134:49322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.harosports.com.tr"] [uri "/.git/config"] [unique_id "amaSdNx2yVn-GQXHnCmTegAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 22:04:20
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 16:40:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 12:39:56.999656 2026] [security2:error] [pid 25579:tid 25579] [client 34.245.21.134:43842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ts-next.link.emmavance.com"] [uri "/.git/config"] [unique_id "amTm3BKQ79jI0R6l4YVb9QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-25 10:47:42
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
4server
2026-07-24 18:45:47
(4 days ago)
[FriJul2420:45:42.3191192026][security2:error][pid3485688:tid3485866][client34.245.21.134:0]ModSecur ...
show more
[FriJul2420:45:42.3191192026][security2:error][pid3485688:tid3485866][client34.245.21.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.traslochiamo.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"amOy1qId8W2EdWrWJaEPrAAAAAw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:11:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:11:50.655317 2026] [security2:error] [pid 3039373:tid 3039373] [client 34.245.21.134:36646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.transport.ic1.biz"] [uri "/.git/config"] [unique_id "amOc1uX5eZLUJjuWmrE6BAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 17:04:57
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 14:55:54
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:45:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:45:45.285344 2026] [security2:error] [pid 1547329:tid 1547329] [client 34.245.21.134:60426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.transcapitalsolutions.internetnameregistration.com"] [uri "/.git/config"] [unique_id "amNeeU2n9HbJfAkwjdExPQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 12:38:26
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:46:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.245.21.134 (ec2-34-245-21-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:46:09.561820 2026] [security2:error] [pid 3923230:tid 3923230] [client 34.245.21.134:55772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trane.cloudex.link"] [uri "/.git/config"] [unique_id "amNQgek80y43CG5XKU7XHgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack