๐ฉ๐ช
webanyone
2026-09-24 19:19:11
(8 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/HEAD | 2026-09-24 19:19 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:51:17
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:51:14.469491 2026] [security2:error] [pid 24554:tid 24554] [client 51.15.108.158:36512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mskimberleesspace.achildsspace.com"] [uri "/.git/HEAD"] [unique_id "arTIYqTe8aMLu5z6LTt4jgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
service Informatique
2026-09-18 04:00:37
(6 days ago)
GET /.env
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 14:54:22
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-17 01:58:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 21:58:35.625357 2026] [security2:error] [pid 32537:tid 32537] [client 51.15.108.158:57280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnic.ladybehindthecurtain.com"] [uri "/.env"] [unique_id "agkgy7qkCv6Yg9NqkgUggQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 00:08:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 20:08:37.652546 2026] [security2:error] [pid 5329:tid 5329] [client 51.15.108.158:46520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nexthop.com"] [uri "/.env"] [unique_id "agkHBVOkyVd6O7Bz_Fqo7wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 23:14:39
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 19:14:33.945302 2026] [security2:error] [pid 4025:tid 4025] [client 51.15.108.158:49812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.forwardti.com"] [uri "/.git/HEAD"] [unique_id "abH3WYE3hRd9ugj5pD0WXQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 17:23:38
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 12:23:31.550600 2026] [security2:error] [pid 13306:tid 13306] [client 51.15.108.158:52404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otfes.com"] [uri "/.git/HEAD"] [unique_id "aV6Wk_z7zmUpgNR3rM1qpAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2025-12-13 18:38:22
(9 months ago)
Accessed trap at '/.git/HEAD'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-22 03:07:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 22:07:38.980033 2025] [security2:error] [pid 451428:tid 451478] [client 51.15.108.158:52038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shop.stonyp.com"] [uri "/.git/HEAD"] [unique_id "aSEo-ozqa_GEMDFtN3tlZQAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-29 09:40:49
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 29 05:40:42.412947 2025] [security2:error] [pid 14166:tid 14166] [client 51.15.108.158:56154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "app.s1global.net.s1global.net"] [uri "/.env"] [unique_id "aNpUGoLj78GxDc_7zeKtmgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2025-09-25 14:49:17
(11 months ago)
51.15.108.158 - - [25/Sep/2025:17:49:14 +0300] "GET /.env HTTP/1.1" 404 2876 "-" "Mozilla/5.0 (Macin ...
show more
51.15.108.158 - - [25/Sep/2025:17:49:14 +0300] "GET /.env HTTP/1.1" 404 2876 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.97 Safari/537.36"
51.15.108.158 - - [25/Sep/2025:17:49:14 +0300] "GET /.env HTTP/1.1" 404 2874 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.97 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
viaccess_orca
2025-09-07 22:01:54
(1 year ago)
Automatic report from Python "IP Blocklist Generator" script
Web Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-05 12:32:52
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.instances.scw.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.instances.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 05 07:32:49.357840 2024] [security2:error] [pid 8720:tid 48001026361088] [client 51.15.108.158:46948] [client 51.15.108.158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.slelectric.com"] [uri "/.git/HEAD"] [unique_id "ZcDVcT8E2NdpKbBu4Az97gAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-03 14:58:23
(2 years ago)
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.instances.scw.clou ...
show more
(mod_security) mod_security (id:210492) triggered by 51.15.108.158 (158-108-15-51.instances.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 03 09:58:16.810195 2024] [security2:error] [pid 24062] [client 51.15.108.158:57198] [client 51.15.108.158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hekom.biz"] [uri "/.env"] [unique_id "ZZV2CC2mUi8idczvQypneQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack