Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=588; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=588; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
π¨π
zynex
2026-07-28 05:24:25
(2 days ago)
URL Probing: /server/.env
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 05:16:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:16:10.451496 2026] [security2:error] [pid 2897266:tid 2897266] [client 47.129.221.182:60838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "banyonsbookdoctor.com"] [uri "/.git/config"] [unique_id "amg7GnSO7Xm-AaN6Js3s5AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 10:42:31
(3 days ago)
Bot detected scanning for vulnerable pages
Port Scan
π©πͺ
BlueWire Hosting
2026-07-27 00:29:35
(3 days ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
πΊπΈ
TPI-Abuse
2026-07-26 23:34:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 19:34:20.275832 2026] [security2:error] [pid 3735615:tid 3735615] [client 47.129.221.182:55730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphadyne.com"] [uri "/.git/config"] [unique_id "amaZfLMQWVk4rCSc-LgufQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-26 23:06:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 19:06:44.352037 2026] [security2:error] [pid 447834:tid 447834] [client 47.129.221.182:48364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphacom.us"] [uri "/.git/config"] [unique_id "amaTBKJmHuyris_CyVNH0AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-24 22:03:14
(5 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-24 11:05:30
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:05:23.974522 2026] [security2:error] [pid 4174868:tid 4174868] [client 47.129.221.182:39678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blazezito.com"] [uri "/.git/config"] [unique_id "amNG8ziN2ROe-AWdQ1jB1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 09:41:52
(6 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-07-24 09:35:02
(6 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 09:06:37
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:06:33.049121 2026] [security2:error] [pid 425606:tid 425606] [client 47.129.221.182:60842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blastjet.net"] [uri "/.git/config"] [unique_id "amMrGYdQXCOYZNYb2j-twwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 07:03:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 47.129.221.182 (ec2-47-129-221-182.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:03:04.395800 2026] [security2:error] [pid 1832886:tid 1832886] [client 47.129.221.182:51180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blanchebb.com"] [uri "/.git/config"] [unique_id "amMOKEQHe3vpOAKswkBCrgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack