Anonymous
2026-07-29 07:00:00
(1 day ago)
Automated Apache web application probing in selected 24h window; attempts=422, unique_paths=211, err ...
show more
Automated Apache web application probing in selected 24h window; attempts=422, unique_paths=211, error_responses=422; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=1073; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1073; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 12:19:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast ...
show more
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:19:39.105986 2026] [security2:error] [pid 2784388:tid 2784388] [client 43.203.140.131:44838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ryzezito.com.blazezito.com"] [uri "/.git/config"] [unique_id "amieW2Ujan-ZBmTa9U6QQwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-28 04:01:48
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Savvii
2026-07-28 00:25:20
(2 days ago)
21 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-28 00:10:05
(2 days ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:06:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast ...
show more
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:06:38.515809 2026] [security2:error] [pid 202649:tid 202649] [client 43.203.140.131:53132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sbxyz.scottwithers.xyz"] [uri "/.git/config"] [unique_id "amfWbkitmxr9i3g__pefZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-27 20:20:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฆ๐บ
Terrier
2026-07-27 18:04:01
(2 days ago)
Blocked for HTTP vulnerability scanning (excessive 404)
Web App Attack
Anonymous
2026-07-27 15:06:22
(2 days ago)
Blocked: Reason='High request volume โ possible DDoS (> 5000 in 60 min)'; Requests=10590
DDoS Attack
๐ณ๐ฑ
Savvii
2026-07-27 13:06:29
(2 days ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dom4k
2026-07-27 06:40:14
(3 days ago)
43.203.140.131 - - [27/Jul/2026:06:40:13 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 ( ...
show more
43.203.140.131 - - [27/Jul/2026:06:40:13 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 04:29:07
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 00:47:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast ...
show more
(mod_security) mod_security (id:210492) triggered by 43.203.140.131 (ec2-43-203-140-131.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 20:47:09.098274 2026] [security2:error] [pid 1668305:tid 1668314] [client 43.203.140.131:48168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.texas-plastic-surgeon.aafm.us"] [uri "/.git/config"] [unique_id "amaqjWMyrzig2-SSjJqXZQAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack