Anonymous
2026-07-25 07:07:13
(12 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-25 05:06:57
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 01:06:53.507585 2026] [security2:error] [pid 1350512:tid 1350512] [client 35.159.173.107:53318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mastersonsmotel.ca"] [uri "/.git/config"] [unique_id "amREbSMKSeLd8Ac7TNK_fAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-25 04:03:34
(15 hours ago)
(modsecurity) srv102 ModSecurity 35.159.173.107 (DE/Germany/ec2-35-159-173-107.eu-central-1.compute. ...
show more
(modsecurity) srv102 ModSecurity 35.159.173.107 (DE/Germany/ec2-35-159-173-107.eu-central-1.compute.amazonaws.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-07-25 03:34:59
(15 hours ago)
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.git/config HTTP/1.1" 403 611 "-" "Mozilla/5.0 ...
show more
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.git/config HTTP/1.1" 403 611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.env HTTP/1.1" 403 611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.env.local HTTP/1.1" 403 611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.env.production HTTP/1.1" 403 611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.159.173.107 - - [25/Jul/2026:05:34:56 +0200] "GET /.env.staging HTTP/1.1" 403 611 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5
...
show less
DDoS Attack
๐ฎ๐น
VHosting
2026-07-25 01:15:03
(18 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 23:50:13
(19 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 04:01:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:01:51.558198 2026] [security2:error] [pid 1857899:tid 1857899] [client 35.159.173.107:46460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pfmarch.com"] [uri "/.git/config"] [unique_id "amLjrx-cI0CyDZqpCA721wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-07-24 04:00:08
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:44:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.159.173.107 (ec2-35-159-173-107.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:44:41.719190 2026] [security2:error] [pid 311857:tid 311900] [client 35.159.173.107:38458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pflagabq.org"] [uri "/.git/config"] [unique_id "amLfqQwevqCJyNVPNDqQWAAAAYw"]
show less
Brute-Force
Bad Web Bot
Web App Attack