Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=1632; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1632; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ฉ๐ช
Savvii
2026-07-27 17:26:22
(2 days ago)
20 attempts against mh-misbehave-ban on train
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 16:53:22
(2 days ago)
(caddyscan) Scanner path probe from 35.177.119.168 (GB/United Kingdom/ec2-35-177-119-168.eu-west-2.c ...
show more
(caddyscan) Scanner path probe from 35.177.119.168 (GB/United Kingdom/ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.177.119.168 - - [27/Jul/2026:16:53:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.177.119.168 - - [27/Jul/2026:16:53:18 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.177.119.168 - - [27/Jul/2026:16:53:18 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.177.119.168 - - [27/Jul/2026:16:53:18 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.177.119.168 - - [27/Jul/2026:16:53:19 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐ซ๐ฎ
mnazibo
2026-07-27 13:15:16
(3 days ago)
Date: Jul 27 16:12:05 2026 EAT | Reported IP: 35.177.119.168 mod_security | id: 920440 930130 932130 ...
show more
Date: Jul 27 16:12:05 2026 EAT | Reported IP: 35.177.119.168 mod_security | id: 920440 930130 932130 932235 932260 933135 934100 934130 942151 942550 949110 920500 | GB/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; URL file extension is restricted by policy; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Found; Remote Comma
show less
SQL Injection
Brute-Force
Bad Web Bot
๐บ๐ธ
CollideTech
2026-07-27 12:52:37
(3 days ago)
probing for vulnerabilities
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 12:49:24
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 10:14:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:13:56.381667 2026] [security2:error] [pid 295593:tid 295593] [client 35.177.119.168:58264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sigi.biz"] [uri "/.git/config"] [unique_id "amcvZOtpGw0FWcaFSp6AZQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-07-27 09:52:31
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:18:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:18:05.882929 2026] [security2:error] [pid 3365692:tid 3365692] [client 35.177.119.168:48978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sifnosgreekcatering.com"] [uri "/.git/config"] [unique_id "amcUPSxkIWa5m5FSY4fpHQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-27 08:09:50
(3 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:01:40
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:01:32.955604 2026] [security2:error] [pid 1548278:tid 1548327] [client 35.177.119.168:51644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siestakeybch.com"] [uri "/.git/config"] [unique_id "amcCTAuCpNubmyDFY0H7wQAAAgo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-27 06:53:21
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:54:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:54:24.546748 2026] [security2:error] [pid 8727:tid 8727] [client 35.177.119.168:58832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierra-broadcasting.com"] [uri "/.git/config"] [unique_id "ambykLvrW7y2eH7sbQJ2GAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:21:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 35.177.119.168 (ec2-35-177-119-168.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:21:45.013129 2026] [security2:error] [pid 3327077:tid 3327077] [client 35.177.119.168:57468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sieder.com"] [uri "/.git/config"] [unique_id "ambc2bb0JbchUWOU3CGpAgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-26 06:39:28
(4 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.staging | 5 distinct paths | UA: Mozilla/5 ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.env.staging | 5 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking