๐ง๐ท
Peregrine
2026-07-30 03:15:06
(2 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03: ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:04 -0300] "GET /.git/config HTTP/1.1" 404 18149
show less
Bad Web Bot
Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=407; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=407; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ง๐ท
Peregrine
2026-07-29 03:14:39
(3 days ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03: ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:04 -0300] "GET /.git/config HTTP/1.1" 404 18149
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-07-28 22:01:52
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-27.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-28 04:31:45
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:02:57
(4 days ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 14:15:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:15:46.745363 2026] [security2:error] [pid 1149364:tid 1149364] [client 35.91.133.236:53740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deckmasterscompany.com"] [uri "/.git/config"] [unique_id "amdoEtz401Ov3TQdLgQ16AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-07-27 13:03:17
(4 days ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:12 -0 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:12 -0300] "GET /api/.env HTTP/1.1" 404 18149
35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:13 -0300] "GET /web/.env HTTP/1.1" 404 18149
35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:13 -0300] "GET /site/.env HTTP/1.1" 404 18149
35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:13 -0300] "GET /public/.env HTTP/1.1" 404 18149
35.91.133.236 104.23.160.19 - - [27/Jul/2026:10:03:13 -0300] "GET /admin/.env HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 12:18:48
(4 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:29:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:29:25.260425 2026] [security2:error] [pid 1571600:tid 1571600] [client 35.91.133.236:42940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debzy.com"] [uri "/.git/config"] [unique_id "amck9W4WYam7RFkqbslKaQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:30:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:30:00.117077 2026] [security2:error] [pid 4136587:tid 4136587] [client 35.91.133.236:59318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debradamico.com"] [uri "/.git/config"] [unique_id "amb66OpN1i3Tpd7GOK53jQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-27 06:13:45
(4 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:11:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:11:13.118485 2026] [security2:error] [pid 28374:tid 28374] [client 35.91.133.236:53844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deborbon.me"] [uri "/.git/config"] [unique_id "amb2gWNEpmn0xZ5flgGjqAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:47:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:47:13.366175 2026] [security2:error] [pid 3890744:tid 3890744] [client 35.91.133.236:58804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deborahbein.com"] [uri "/.git/config"] [unique_id "ambw4TPzBPdc_AEN42X3_AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:09:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.91.133.236 (ec2-35-91-133-236.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:09:35.273985 2026] [security2:error] [pid 2621018:tid 2621018] [client 35.91.133.236:44146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debhill.alhill.com"] [uri "/.git/config"] [unique_id "ambZ_04OyqT48pcUEWeVgQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack