Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=1223; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.e ...
show more
Apache probe; attempts=1223; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-26 08:24:45
(5 days ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-07-26 07:02:25
(5 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 52.214.170 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 52.214.170.57 (IE/Ireland/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 52.214.170.57 (IE/Ireland/ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 04:00:27
(5 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 02:24:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 22:24:42.693347 2026] [security2:error] [pid 3404378:tid 3404389] [client 52.214.170.57:51936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sattraffic.net"] [uri "/.git/config"] [unique_id "amVv6sIpmTsXMl8fv4SaWQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:05:47
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-07-25 05:15:10
(6 days ago)
251 attacks on PHP URLs, config grabbing URLs (type 2), env grabbing URLs, VC URLs:
GET /includes/ph ...
show more
251 attacks on PHP URLs, config grabbing URLs (type 2), env grabbing URLs, VC URLs:
GET /includes/phpinfo.php HTTP/1.1
GET /application_default_credentials.json HTTP/1.1
GET /config/app/.env HTTP/1.1
GET /.git/config HTTP/1.1
show less
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:03:52
(6 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 15:18:08
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:17:59.806468 2026] [security2:error] [pid 421768:tid 421768] [client 52.214.170.57:33124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purebinary.cathrynn.com"] [uri "/.git/config"] [unique_id "amOCJ-4O2yDRWS2_eAxRHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:55:52
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:55:44.509112 2026] [security2:error] [pid 3306:tid 3306] [client 52.214.170.57:35396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pumps.aguasolar.com"] [uri "/.git/config"] [unique_id "amNu4JkxNX8986SZbd6zggAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:25:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:25:34.821112 2026] [security2:error] [pid 2487:tid 2487] [client 52.214.170.57:35996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.puckerbikinis.puckerbikini.com"] [uri "/.git/config"] [unique_id "amNZvpDoBGcDs2SlmNBnkgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:55:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 52.214.170.57 (ec2-52-214-170-57.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:55:26.781747 2026] [security2:error] [pid 16725:tid 16725] [client 52.214.170.57:42080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.publication.flyingdodostudio.com"] [uri "/.git/config"] [unique_id "amNSroiyhe3NOtsa6MQBtQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 10:04:36
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
dynamix
2026-07-24 09:52:11
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-24 09:34:00
(1 week ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH