๐บ๐ธ
CollideTech
2026-07-27 19:33:06
(8 hours ago)
found poking around where they should not be
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 17:39:41
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 13:39:35.558197 2026] [security2:error] [pid 1089974:tid 1089974] [client 100.31.153.48:49488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagineyourphotos.com"] [uri "/.git/config"] [unique_id "ameX13GAQioPgLjPmX2VLgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 16:21:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:21:17.246222 2026] [security2:error] [pid 3690055:tid 3690055] [client 100.31.153.48:39292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imaginationbyme.com"] [uri "/.git/config"] [unique_id "ameFfas7lGv7tf_8p3Qm7wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 14:53:19
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:53:15.628598 2026] [security2:error] [pid 3717995:tid 3717995] [client 100.31.153.48:40876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagesbyaubrey.com"] [uri "/.git/config"] [unique_id "amdw2xSXH_XOAGgKjjmb6gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-07-27 13:23:30
(15 hours ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-166)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 11:16:01
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:15:58.109351 2026] [security2:error] [pid 3170538:tid 3170538] [client 100.31.153.48:57052] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||imageries.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "imageries.net"] [uri "/.env.bak"] [unique_id "amc97lrSI5gHOMBlk6qXAQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:37:29
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:37:25.354795 2026] [security2:error] [pid 3130388:tid 3130388] [client 100.31.153.48:34802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imagea.net"] [uri "/.git/config"] [unique_id "amcm1QTtxWqVnXGH5dUCBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-07-27 04:50:47
(23 hours ago)
100.31.153.48 - - [27/Jul/2026:06:50:46 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 ...
show more
100.31.153.48 - - [27/Jul/2026:06:50:46 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:00:35
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 10:10:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:10:26.388389 2026] [security2:error] [pid 156542:tid 156542] [client 100.31.153.48:49484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecuablue.farm"] [uri "/.git/config"] [unique_id "amM6ElDeOcvQSOiSHM378gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:21:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:21:48.155154 2026] [security2:error] [pid 497375:tid 497391] [client 100.31.153.48:57932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecothermtech.com"] [uri "/.git/config"] [unique_id "amMurIAbQJAkk99KohMjUwAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:31:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:31:44.228915 2026] [security2:error] [pid 18436:tid 18436] [client 100.31.153.48:52476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "economy-cleaners.com"] [uri "/.git/config"] [unique_id "amMi8E4YpItzit5thxJzcQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 08:12:11
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:38:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.153.48 (ec2-100-31-153-48.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:38:48.854498 2026] [security2:error] [pid 3637798:tid 3637798] [client 100.31.153.48:41734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ecodesarrollourbano.com"] [uri "/.git/config"] [unique_id "amMIeAfXGvKiO-wTFP6mKwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 06:02:59
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack