Anonymous
2026-07-27 07:35:41
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฟ
Tripwire
2026-07-26 07:49:50
(1 day ago)
Scanning for exploits - /.env
Web App Attack
๐บ๐ธ
mnsf
2026-07-26 04:05:04
(1 day ago)
Scanning/Probing (40)
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 03:47:00
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/drupal/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 02:31:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 22:31:25.089387 2026] [security2:error] [pid 1215997:tid 1215997] [client 54.224.69.208:41078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maryrosevaro.com"] [uri "/.git/config"] [unique_id "amVxfY094s7NK_HPE1ERPgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:07:09
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 06:39:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 02:39:42.880713 2026] [security2:error] [pid 2382237:tid 2382237] [client 54.224.69.208:50092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kevindennisins.com"] [uri "/.git/config"] [unique_id "amRaLoC_Nz88EmO3y_x9vgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 06:37:57
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 04:58:19
(2 days ago)
[da.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.git ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.example.com; logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-07-25 02:20:05
(2 days ago)
Auto-blocked: score 988 (threshold 10). Tier: HIGH. Hits: 224. Flags: phpinfo, info-file, error-scan ...
show more
Auto-blocked: score 988 (threshold 10). Tier: HIGH. Hits: 224. Flags: phpinfo, info-file, error-scan, joomla-admin, server-info, server-status, backup-file, test-file, env-file, git-exposure, mysql-probe, joomla-probe. Paths: /staging/phpinfo.php, /beta/phpinfo.php, /uat/phpinfo.php, /qa/phpinfo.php, /preview/phpinfo.php
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 00:33:48
(2 days ago)
(caddyscan) Scanner path probe from 54.224.69.208 (US/United States/ec2-54-224-69-208.compute-1.amaz ...
show more
(caddyscan) Scanner path probe from 54.224.69.208 (US/United States/ec2-54-224-69-208.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 54.224.69.208 - - [25/Jul/2026:00:33:44 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 54.224.69.208 - - [25/Jul/2026:00:33:44 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 54.224.69.208 - - [25/Jul/2026:00:33:44 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 54.224.69.208 - - [25/Jul/2026:00:33:44 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 54.224.69.208 - - [25/Jul/2026:00:33:45 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 12:19:26
(2 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:52:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:52:14.667117 2026] [security2:error] [pid 3800852:tid 3800852] [client 54.224.69.208:52714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newlife12steprecovery.org"] [uri "/.git/config"] [unique_id "amM1zoV1iyjlrx1SauRCeAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-24 08:05:41
(3 days ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 07:45:01
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.224.69.208 (ec2-54-224-69-208.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:44:54.026917 2026] [security2:error] [pid 4113446:tid 4113446] [client 54.224.69.208:37134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newcastle91.org"] [uri "/.git/config"] [unique_id "amMX9jxFOHd0DuPoFTRJgQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack