π³π±
Site.eu
2026-09-01 10:39:13
(2 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-01 10:07:06
(2 days ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-01 09:46:49.
Web App Attack
π³π±
e.fierstra
2026-09-01 09:30:56
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 08:25:07
(2 days ago)
Bot / scanning and/or hacking attempts: GET /core/app/.env HTTP/1.1, GET /apps/.env HTTP/1.1, GET /s ...
show more
Bot / scanning and/or hacking attempts: GET /core/app/.env HTTP/1.1, GET /apps/.env HTTP/1.1, GET /site/.env HTTP/1.1, GET /src/.env HTTP/1.1, GET /.env.yml HTTP/1.1, GET /core/.env HTTP/1.1, GET /application/.env HTTP/1.1, GET /web/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /app/.env HTTP/1.1, GET /config/.env HTTP/1.1, GET /private/.env HTTP/1.1, GET /server/.env HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /.env2 HTTP/1.1, GET /admin/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.prod HTTP/1.1, GET /public/.env HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /.env.dev HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 07:59:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:59:02.910784 2026] [security2:error] [pid 27758:tid 27758] [client 8.234.28.106:44590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeswecanhandyservices.com"] [uri "/.git/config"] [unique_id "apaFxqYoyeeLibA7yR2vYQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-01 07:03:14
(2 days ago)
Multiple WAF Violations
Web App Attack
π©πͺ
zumbo.net
2026-09-01 06:47:10
(2 days ago)
[Tue Sep 01 09:47:09.699221 2026] [proxy_fcgi:error] [pid 234468:tid 234480] [client 8.234.28.106:0] ...
show more
[Tue Sep 01 09:47:09.699221 2026] [proxy_fcgi:error] [pid 234468:tid 234480] [client 8.234.28.106:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 01 09:47:09.828476 2026] [proxy_fcgi:error] [pid 234469:tid 234481] [client 8.234.28.106:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 01 09:47:09.959736 2026] [proxy_fcgi:error] [pid 260377:tid 260392] [client 8.234.28.106:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 01 09:47:10.088137 2026] [proxy_fcgi:error] [pid 260377:tid 260394] [client 8.234.28.106:0] AH01071: Got error 'Primary script unknown'
[Tue Sep 01 09:47:10.219023 2026] [proxy_fcgi:error] [pid 234469:tid 234502] [client 8.234.28.106:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 05:46:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:46:44.340475 2026] [security2:error] [pid 12725:tid 12725] [client 8.234.28.106:38942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yerevanpress.am"] [uri "/.git/config"] [unique_id "apZmxK7s93FNZ2lzaKGdKwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:37:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:37:13.687598 2026] [security2:error] [pid 3601135:tid 3601318] [client 8.234.28.106:33374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yellowsunset.com.appraisalteam.net"] [uri "/.git/config"] [unique_id "apZIaTXTCLp4H1pGL-uKYQAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-01 02:05:08
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 01:28:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:28:13.065672 2026] [security2:error] [pid 16928:tid 16928] [client 8.234.28.106:59842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yeejia.net"] [uri "/.git/config"] [unique_id "apYqLTWfoFHvMlhcZHNhhQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-08-31 09:05:26
(3 days ago)
Too many Status 40X (14)
Scanning/Probing (14)
Brute-Force
Web App Attack
π³π±
middelkoopcc
2026-08-31 08:49:01
(3 days ago)
2026-08-31 10:46:51 GET /.git/config [301] && 2026-08-31 10:46:51 GET /.env [301] && 2026-08-31 10:4 ...
show more
2026-08-31 10:46:51 GET /.git/config [301] && 2026-08-31 10:46:51 GET /.env [301] && 2026-08-31 10:46:55 GET /app/.env [301] && 214 more within 20 minutes
show less
Web App Attack
π³π±
Site.eu
2026-08-31 06:41:20
(3 days ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-31 04:54:35
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.28.106 (106.28.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:54:31.099471 2026] [security2:error] [pid 32145:tid 32145] [client 8.234.28.106:60812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yevid.com"] [uri "/.git/config"] [unique_id "apUJB3KGtOmZwsyQngPQGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack