๐ณ๐ฑ
Site.eu
2026-09-22 08:46:17
(21 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
masterguru
2026-09-22 05:56:55
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-21 23:55:43
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:01:56
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
๐ซ๐ท
Octopuce
2026-09-20 23:37:12
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
kosada.com
2026-09-20 17:30:46
(2 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 16:58:20
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
LRob
2026-09-16 07:39:58
(6 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env | 2026-09-16 07:39 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:37:04
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:36:59.895302 2026] [security2:error] [pid 25755:tid 25755] [client 8.230.11.224:49162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "maricotippett.com"] [uri "/.env"] [unique_id "aqoAywwHbC9dr-JZ_afgIgAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:00:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:00:43.335645 2026] [security2:error] [pid 24932:tid 24932] [client 8.230.11.224:54254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lejzerowicz.org"] [uri "/.env"] [unique_id "aqnqO7iVKQKbWiQhwlUEFgAAABU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 22:05:27
(1 week ago)
8.230.11.224 - - [15/Sep/2026:22:04:29 +0000] "GET /.remote HTTP/1.1" 403 18292 "https://www.google. ...
show more
8.230.11.224 - - [15/Sep/2026:22:04:29 +0000] "GET /.remote HTTP/1.1" 403 18292 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/19.0.351.18 Safari/536.12" "-" edge="8.230.11.224"
8.230.11.224 - - [15/Sep/2026:22:04:31 +0000] "GET /.local HTTP/1.1" 403 18272 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/19.0.351.18 Safari/536.12" "-" edge="8.230.11.224"
8.230.11.224 - - [15/Sep/2026:22:04:32 +0000] "GET /.production HTTP/1.1" 403 18265 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/19.0.351.18 Safari/536.12" "-" edge="8.230.11.224"
8.230.11.224 - - [15/Sep/2026:22:04:33 +0000] "GET //vendor/.env HTTP/1.1" 403 12 "https://www.google.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_4) AppleWebKit/535.7 (KHTML, like Gecko) Chrome/19.0.351.18 Safari/536.12" "-" edge="8.230.11.
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:17:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:17:05.320445 2026] [security2:error] [pid 26561:tid 26561] [client 8.230.11.224:53516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fashionmenswear.com"] [uri "/.env"] [unique_id "aql9kcVZmscjDUrI083kDAAAABg"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 17:02:32
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 11:20:09
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:05:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.11.224 (224.11.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:05:32.193547 2026] [security2:error] [pid 24961:tid 24961] [client 8.230.11.224:43658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemoulinavent.org"] [uri "/.env"] [unique_id "aqkmfH_kkTfEDRF0JkULVQAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack