๐ฉ๐ช
webanyone
2026-09-24 19:19:11
(23 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/HEAD | 2026-09-24 19:19 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 02:47:54
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 22:47:46.713178 2026] [security2:error] [pid 7531:tid 7612] [client 51.158.163.135:58070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.theworldinstituteofslowness.com"] [uri "/.git/HEAD"] [unique_id "aoe8UohfXbhKhcHPQipLrAAAA1M"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 16:11:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 12:11:22.358517 2026] [security2:error] [pid 2960:tid 2960] [client 51.158.163.135:45560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mayiasteadman.com.my-spec.com"] [uri "/.git/HEAD"] [unique_id "aocnKsd_WWYa5y0Ody_bSAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Ar1s
2026-08-12 14:58:42
(1 month ago)
[1:2610542] TGI HUNT gitrepo HTTP Probe ::: Port: 80/TCP
Exploited Host
๐ฉ๐ช
Gwyneth Llewelyn
2026-07-23 06:43:31
(2 months ago)
51.158.163.135 - - [23/Jul/2026:07:43:20 +0100] "GET /.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 (Macin ...
show more
51.158.163.135 - - [23/Jul/2026:07:43:20 +0100] "GET /.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.97 Safari/537.36"
2026/07/23 07:43:29 [error] 1770200#1770200: *897106 access forbidden by rule, client: 51.158.163.135, server: [redacted], request: "GET /.env HTTP/2.0", host: "fashcon.betatechnologies.info"
51.158.163.135 - - [23/Jul/2026:07:43:29 +0100] "GET /.env HTTP/2.0" 403 1045 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.97 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-07-23 03:40:48
(2 months ago)
2026/07/23 04:40:47 [error] 1770200#1770200: *867030 access forbidden by rule, client: 51.158.163.13 ...
show more
2026/07/23 04:40:47 [error] 1770200#1770200: *867030 access forbidden by rule, client: 51.158.163.135, server: bot.betatechnologies.info, request: "GET /.env HTTP/2.0", host: "bot.betatechnologies.info"
2026/07/23 04:40:46 [error] 1770200#1770200: *867029 access forbidden by rule, client: 51.158.163.135, server: projects.betatechnologies.info, request: "GET /.env HTTP/2.0", host: "projects.betatechnologies.info"
51.158.163.135 - - [23/Jul/2026:04:40:47 +0100] "GET /.env HTTP/2.0" 403 138 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.97 Safari/537.36"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 01:56:05
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 21:56:02.331565 2026] [security2:error] [pid 16111:tid 16111] [client 51.158.163.135:36038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jobs.evolute.io"] [uri "/.env"] [unique_id "amF0sh-fVoWqWV9OP_XpbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-16 17:30:19
(4 months ago)
Blocked by UFW (TCP on 80)
Source port: 46396
TTL: 54
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 46396
TTL: 54
Packet length: 60
TOS: 0x00
This report (for 51.158.163.135) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 02:52:56
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.rev.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 02 21:52:53.143990 2026] [security2:error] [pid 14596:tid 14596] [client 51.158.163.135:54710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maleein.com"] [uri "/.env"] [unique_id "aViEhbh8ZMhU-3jv2A9AywAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gu-alvareza
2025-10-28 07:05:04
(10 months ago)
Nmap.Script.Scanner
Port Scan
๐บ๐ธ
TPI-Abuse
2025-07-27 15:31:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.instances.scw.cl ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.instances.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 27 11:30:57.819202 2025] [security2:error] [pid 26772:tid 26772] [client 51.158.163.135:45920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.wisdomwfm.com"] [uri "/.env"] [unique_id "aIZGMZ_ymwChuABnsPkkZgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 13:09:10
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.instances.scw.cl ...
show more
(mod_security) mod_security (id:210492) triggered by 51.158.163.135 (135-163-158-51.instances.scw.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 27 09:09:04.123663 2025] [security2:error] [pid 32415:tid 32415] [client 51.158.163.135:36906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.megapct.com"] [uri "/.env"] [unique_id "aIYk8MSm_NVCJAv4DQcJ0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2025-07-15 21:12:34
(1 year ago)
Accessed trap at '/docker-compose.yml'
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2025-06-25 20:10:10
(1 year ago)
Detected as a bad bot
Bad Web Bot
๐ง๐ช
voormedia
2025-06-24 08:47:59
(1 year ago)
Accessed trap at '/.env'
Web App Attack