Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=204; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.json | /.env.live | /.env.local | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.remote | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | /bin/.env | /bootstrap/.env | /brevo/.env | /build/.env | /buildkite/.env | /bulk/.env | /cache/.en | ... [204 exact paths total]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 19:12:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:12:04.860173 2026] [security2:error] [pid 4180755:tid 4180755] [client 54.226.38.195:55558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.betnbet.ag"] [uri "/.git/config"] [unique_id "amethIwAbK-l8_PobWIIGQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 17:49:42
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-27 16:35:30
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 54.226.38.195 (US/United States/ec2-54-226-38-1 ...
show more
(mod_security) mod_security (id:949110) triggered by 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-07-27 16:12:34
(3 days ago)
(modsecurity) srv201 ModSecurity 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazona ...
show more
(modsecurity) srv201 ModSecurity 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
SysAdmin Dylan
2026-07-27 15:49:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (US/United States/ec2-54-226-38-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 10 in the last 3600 secs
show less
Brute-Force
Anonymous
2026-07-27 15:07:29
(3 days ago)
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amaz ...
show more
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:15:07:25 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:15:07:25 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:15:07:25 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:15:07:25 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:15:07:25 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 14:06:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:06:05.486195 2026] [security2:error] [pid 592792:tid 592792] [client 54.226.38.195:43454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bbrd.net"] [uri "/.git/config"] [unique_id "amdlzRgz1VWv5iuZzd3PMAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2026-07-27 13:56:08
(3 days ago)
(ScanningForFiles) Scanning for files triggerd 54.226.38.195 (US/United States/ec2-54-226-38-195.com ...
show more
(ScanningForFiles) Scanning for files triggerd 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 10 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-07-27 07:35:23
(3 days ago)
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amaz ...
show more
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:07:35:18 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:07:35:18 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:07:35:18 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:07:35:18 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:07:35:18 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 05:54:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:54:08.667312 2026] [security2:error] [pid 110972:tid 110972] [client 54.226.38.195:52856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.awcadvocate.com"] [uri "/.git/config"] [unique_id "ambygDTFUYe15A9lOXuMjgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 04:26:22
(3 days ago)
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amaz ...
show more
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:04:26:21 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:04:26:21 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:04:26:21 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:04:26:21 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [27/Jul/2026:04:26:21 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 04:20:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.226.38.195 (ec2-54-226-38-195.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:20:51.406288 2026] [security2:error] [pid 2823755:tid 2823755] [client 54.226.38.195:53892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.avaliantlife.com"] [uri "/.git/config"] [unique_id "ambco57vKxxxmg6dtYiglgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 05:51:26
(4 days ago)
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amaz ...
show more
(caddyscan) Scanner path probe from 54.226.38.195 (US/United States/ec2-54-226-38-195.compute-1.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 54.226.38.195 - - [26/Jul/2026:05:51:24 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [26/Jul/2026:05:51:24 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [26/Jul/2026:05:51:24 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [26/Jul/2026:05:51:24 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 54.226.38.195 - - [26/Jul/2026:05:51:24 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
4server
2026-07-26 05:26:54
(4 days ago)
[SunJul2607:26:51.9712242026][security2:error][pid1068034:tid1068059][client54.226.38.195:0]ModSecur ...
show more
[SunJul2607:26:51.9712242026][security2:error][pid1068034:tid1068059][client54.226.38.195:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"mail.mood4apps.com.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"amWamwbcb5QxACBp60voTAAAAI8\"]
show less
Port Scan
Brute-Force
Web App Attack