Anonymous
2026-07-29 07:00:00
(4 hours ago)
Apache probe; attempts=420; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=420; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.bak | /.env.ci | /.env.dev | /.env.development | /.env.dist | /.env.docker | /.env.example | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.neon | /.env.old | /.env.preprod | /.env.prod | /.env.production | /.env.railway | /.env.remote | /.env.render | /.env.sample | /.env.save | /.env.stage | /.env.staging | /.env.supabase | /.env.swp | /.env.test | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env~ | /.git/.env | /.git/config | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/.env | /api/dev/.env | /api/staging/.env | /api/v1/.env | /api/v2/.env | /api/v3/.env | /app/.env | /application/.env | /apps/.env | /assets/.env | /aws/.env | /azure/.env | /backend/.env | /backup/.env | /backups/.env | /beta/.env | ... [211 exact paths total]
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 03:47:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 23:47:09.529834 2026] [security2:error] [pid 14264:tid 14264] [client 98.94.89.53:37164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lovestuff.net"] [uri "/.git/config"] [unique_id "amgmPXJswXyuV8CYvwjaAQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 02:23:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:23:08.137086 2026] [security2:error] [pid 1948344:tid 1948344] [client 98.94.89.53:37528] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "love-n-promises.com"] [uri "/.git/config"] [unique_id "amgSjJKXq1hWBW9g5znaRwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-26 22:04:22
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-25.
show less
Web App Attack
SSH
Hacking
π³π±
homeshowdomain.nl
2026-07-25 22:01:26
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
π³π±
Site.eu
2026-07-25 06:18:19
(4 days ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-24 10:13:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:13:24.593514 2026] [security2:error] [pid 497375:tid 497380] [client 98.94.89.53:58174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "upperwilds.com"] [uri "/.git/config"] [unique_id "amM6xIAbQJAkk99KohMqPgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 09:51:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaw ...
show more
(mod_security) mod_security (id:210492) triggered by 98.94.89.53 (ec2-98-94-89-53.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:51:01.979531 2026] [security2:error] [pid 3577628:tid 3577628] [client 98.94.89.53:49486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "upperbearcreek.net"] [uri "/.git/config"] [unique_id "amM1hdSqbTJzBqUw-ylhAgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-24 08:10:24
(5 days ago)
Multiple WAF Violations
Web App Attack