๐ฌ๐ง
consul.to
2026-02-15 12:49:53
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-02-15 12:04:02
(3 months ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /dev/.git/config HTTP/1.1, GE ...
show more
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /dev/.git/config HTTP/1.1, GET /v2/.git/config HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /backend/.env HTTP/1.1, HEAD / HTTP/1.1, GET /test/.git/config HTTP/1.1, GET /site/.git/config HTTP/1.1, GET /.aws/credentials HTTP/1.1, GET /api/.git/config HTTP/1.1, GET /config/.env HTTP/1.1, GET /.env.staging HTTP/1.1, GET /new/.git/config HTTP/1.1, GET /app/.git/config HTTP/1.1, GET /wp/.git/config HTTP/1.1, GET /backup/.git/config HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-02-15 11:41:40
(3 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Hacking
Web App Attack
๐ฉ๐ช
Mario Silber
2026-02-15 11:15:08
(3 months ago)
(mod_security) mod_security triggered on hostname [redacted] 45.3.54.212 (GB/United Kingdom/-)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-02-15 05:51:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 00:51:20.811831 2026] [security2:error] [pid 340110:tid 340110] [client 45.3.54.212:14933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swetzer.net"] [uri "/backend/.env"] [unique_id "aZFe2K0yRPGmkVUWF4ijmAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 04:20:26
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:20:05.463232 2026] [security2:error] [pid 18235:tid 18235] [client 45.3.54.212:59347] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "strawusa.com"] [uri "/site/.git/config"] [unique_id "aZFJdTpFoQAaY0TAlwrFAQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 03:43:00
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:42:54.702221 2026] [security2:error] [pid 18563:tid 18563] [client 45.3.54.212:41059] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "step1nutrition.com"] [uri "/test/.git/config"] [unique_id "aZFAvv0SLTOUZjdP3bddNQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:15:08
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:15:02.553285 2026] [security2:error] [pid 12326:tid 12326] [client 45.3.54.212:19647] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "speakertrainerconsultantpatdavis.org"] [uri "/.env.save"] [unique_id "aZEsJsB6ytgn23JOwH9rrQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:51:19
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:51:15.313118 2026] [security2:error] [pid 27203:tid 27203] [client 45.3.54.212:11503] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "myclassicvw.com"] [uri "/.env.save"] [unique_id "aZEmk73EjmvVb_xWIcwSwwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:29:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:28:58.349341 2026] [security2:error] [pid 15894:tid 15894] [client 45.3.54.212:36471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "musicfreakcentral.com"] [uri "/.env"] [unique_id "aZEhWgDGiFhWLiGzKBli1QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-02-15 01:05:41
(3 months ago)
Too many Status 40X (12)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-15 00:49:54
(3 months ago)
Try to access /backup/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 00:45:01
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:44:55.457122 2026] [security2:error] [pid 1051256:tid 1051256] [client 45.3.54.212:39671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moyworld.com"] [uri "/api/.git/config"] [unique_id "aZEXB6rLdhMl9_p43t1DGAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 00:17:12
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:17:06.533972 2026] [security2:error] [pid 636044:tid 636044] [client 45.3.54.212:20155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "loudenlow.com"] [uri "/admin/.env"] [unique_id "aZEQghpyg9IGoJpuPDIbkAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-14 23:24:58
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.54.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:24:50.935131 2026] [security2:error] [pid 7016:tid 7016] [client 45.3.54.212:22413] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liwlra.org"] [uri "/backup/.git/config"] [unique_id "aZEEQuHkWuuzSdflOuNUpAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack