Anonymous
2026-07-29 07:00:00
(12 hours ago)
Automated Apache web application probing in selected 24h window; attempts=211, unique_paths=211, err ...
show more
Automated Apache web application probing in selected 24h window; attempts=211, unique_paths=211, error_responses=184; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(12 hours ago)
Apache probe; attempts=422; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=422; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 04:55:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 00:55:03.484840 2026] [security2:error] [pid 374000:tid 374000] [client 35.180.63.82:34590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hollywoo7.exotic-dancers-los-angeles.com"] [uri "/.git/config"] [unique_id "amg2J1fP6VPb5IyrmU1hGwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-27 22:03:44
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
π³π±
Site.eu
2026-07-27 20:56:13
(1 day ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
kosada.com
2026-07-27 19:29:22
(1 day ago)
Web vulnerability probing: /api/dev/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 18:18:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:18:45.804529 2026] [security2:error] [pid 23135:tid 23140] [client 35.180.63.82:60942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iguanablue.newleafpro.com"] [uri "/.git/config"] [unique_id "amehBZbWjPH1bo6pUq_1VgAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 14:01:19
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 10:31:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.180.63.82 (ec2-35-180-63-82.eu-west-3.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:30:52.763628 2026] [security2:error] [pid 2318222:tid 2318415] [client 35.180.63.82:48332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ieho.wwwhst.com"] [uri "/.git/config"] [unique_id "amczXCrkGO2D6eM_2uyvCgAAAdE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-07-27 03:10:31
(2 days ago)
Web attack/malicious scanning detected
Web App Attack