๐ณ๐ฑ
Site.eu
2026-07-27 10:48:50
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-07-27 09:20:02
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 08:03:05
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ง๐พ
lns.bz
2026-07-27 06:42:25
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:35:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:35:29.982694 2026] [security2:error] [pid 19915:tid 19915] [client 54.147.173.217:33604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ypsisda.net"] [uri "/.git/config"] [unique_id "amb8MSecy4AI21aQvwExwAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 05:33:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 01:33:09.306285 2026] [security2:error] [pid 3252:tid 3261] [client 54.147.173.217:36992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yt.kd9uri.com"] [uri "/.git/config"] [unique_id "amWcFa6Cx56tn6QOA9pxBQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-07-26 05:30:09
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-07-26 02:25:01
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-07-25 00:05:50
(3 days ago)
Too many Status 40X (36)
Scanning/Probing (36)
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 16:20:55
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-07-24 15:05:48
(3 days ago)
Abuse Detected (4)
Brute-Force
Web App Attack
Anonymous
2026-07-24 13:40:04
(4 days ago)
Bot / scanning and/or hacking attempts: GET /.env.yaml HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env. ...
show more
Bot / scanning and/or hacking attempts: GET /.env.yaml HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env.dist HTTP/1.1, GET /.env.yml HTTP/1.1, GET /app/.env HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.staging HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env1 HTTP/1.1, GET /apps/.env HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.uat HTTP/1.1, GET /.env.swp HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env.sample HTTP/1.1, GET /.env.prod HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
zumbo.net
2026-07-24 13:14:33
(4 days ago)
[Fri Jul 24 16:14:31.993875 2026] [proxy_fcgi:error] [pid 1087875:tid 1087889] [client 54.147.173.21 ...
show more
[Fri Jul 24 16:14:31.993875 2026] [proxy_fcgi:error] [pid 1087875:tid 1087889] [client 54.147.173.217:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 24 16:14:32.106865 2026] [proxy_fcgi:error] [pid 1087875:tid 1087892] [client 54.147.173.217:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 24 16:14:32.214051 2026] [proxy_fcgi:error] [pid 1087875:tid 1087881] [client 54.147.173.217:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 24 16:14:32.320866 2026] [proxy_fcgi:error] [pid 1087875:tid 1087885] [client 54.147.173.217:0] AH01071: Got error 'Primary script unknown'
[Fri Jul 24 16:14:32.428032 2026] [proxy_fcgi:error] [pid 1087875:tid 1087899] [client 54.147.173.217:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:35:38
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 54.147.173.217 (ec2-54-147-173-217.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:35:33.916018 2026] [security2:error] [pid 3805:tid 3805] [client 54.147.173.217:37820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yaufung.naturev.net"] [uri "/.git/config"] [unique_id "amM_9ShlLc-M_Bzi1DUljAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 09:28:56
(4 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack