Anonymous
2026-07-29 07:00:00
(22 hours ago)
Apache probe; attempts=624; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=624; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-28 22:02:05
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 13:48:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:48:19.927088 2026] [security2:error] [pid 9127:tid 9127] [client 52.91.25.105:58842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heaven.avmcyber.com"] [uri "/.git/config"] [unique_id "amdho1_a8iDaY-4QfzGGAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-27 13:43:10
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฌ๐ง
cg-design.co.uk
2026-07-27 11:50:27
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 52.91.25.105 (US/United States/ec2-52-9 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 52.91.25.105 (US/United States/ec2-52-91-25-105.compute-1.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-27 11:04:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:04:14.219970 2026] [security2:error] [pid 9872:tid 9872] [client 52.91.25.105:54758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heathbartley.com"] [uri "/.git/config"] [unique_id "amc7LpitMVYrkWoAEgWK2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Savvii
2026-07-27 10:32:14
(2 days ago)
20 attempts against mh-misbehave-ban on heat
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:46:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:45:58.877173 2026] [security2:error] [pid 42078:tid 42078] [client 52.91.25.105:45434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heartshapedboy.com"] [uri "/.git/config"] [unique_id "amco1j8bDgmSS9Js90ol8AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:00:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:59:56.141389 2026] [security2:error] [pid 1688620:tid 1688699] [client 52.91.25.105:45364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heartfailuredev.howiek.com"] [uri "/.git/config"] [unique_id "amcP_HaXIRKgyharhhjiAwAAAdQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-27 06:07:33
(2 days ago)
52.91.25.105 - - [27/Jul/2026:09:07:32 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 ( ...
show more
52.91.25.105 - - [27/Jul/2026:09:07:32 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.91.25.105 - - [27/Jul/2026:09:07:33 +0300] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:10:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:10:28.107534 2026] [security2:error] [pid 1163353:tid 1163353] [client 52.91.25.105:33042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthydatasystems.com"] [uri "/.git/config"] [unique_id "ambaNJT8vutln9u90y3e0wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-26 04:57:12
(4 days ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 04:02:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 00:02:45.647955 2026] [security2:error] [pid 3168726:tid 3168726] [client 52.91.25.105:56570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hpepaper.com"] [uri "/.git/config"] [unique_id "amWG5QbWFTi0AdnbABfNywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:29:18
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazon ...
show more
(mod_security) mod_security (id:210492) triggered by 52.91.25.105 (ec2-52-91-25-105.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:29:10.496663 2026] [security2:error] [pid 311761:tid 311827] [client 52.91.25.105:44818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "culturallyyours.org.lamco.us"] [uri "/.git/config"] [unique_id "amL4Ju9YDRBkwHt3sEHhGgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 03:30:04
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack