๐ฉ๐ช
dave
2026-07-19 22:07:47
(2 hours ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config targets=cloud hit_count=3 first_seen=2026-07-19T22:07:47Z last_seen=2026-07-19T22:07:47Z
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-19 22:02:20
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-18.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-19 21:47:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 17:47:28.055318 2026] [security2:error] [pid 3741:tid 3741] [client 100.31.253.201:39772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quinlaneducationfoundation.com"] [uri "/.git/config"] [unique_id "al1F8PShYHlDVMC9KNm6BQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-19 20:42:09
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
Rip
2026-07-19 19:47:11
(5 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 18:11:51
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 14:11:45.800074 2026] [security2:error] [pid 3593811:tid 3593811] [client 100.31.253.201:44584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "destintoday.com"] [uri "/.env"] [unique_id "al0TYaYFqHqxIFiVCHHW-gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-07-19 18:00:04
(6 hours ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-19 17:27:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:27:34.214873 2026] [security2:error] [pid 5453:tid 5453] [client 100.31.253.201:38578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goseethenurse.com"] [uri "/.git/config"] [unique_id "al0JBndDSBclY7Lhqp0XJwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 17:00:04
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 12:59:54.655314 2026] [security2:error] [pid 2706338:tid 2706338] [client 100.31.253.201:58060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryfeil.com"] [uri "/.git/config"] [unique_id "al0CiqepWaOJZWoDJ_rL0AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 16:18:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 12:18:12.966411 2026] [security2:error] [pid 26409:tid 26409] [client 100.31.253.201:38192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chefmarcelcooks.com"] [uri "/.git/config"] [unique_id "alz4xCtRVXPgxoQKzjsZ6QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 15:13:21
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 11:13:16.766146 2026] [security2:error] [pid 25538:tid 25559] [client 100.31.253.201:43190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.icert.io"] [uri "/.git/config"] [unique_id "alzpjL72wusjXcXIVNDkAAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 12:18:51
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.am ...
show more
(mod_security) mod_security (id:210492) triggered by 100.31.253.201 (ec2-100-31-253-201.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 08:18:45.550597 2026] [security2:error] [pid 22652:tid 22652] [client 100.31.253.201:42252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intothebigempty.com"] [uri "/.env"] [unique_id "alzApeUWpPO669PqWiNkLwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 09:05:03
(15 hours ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=30
Hacking
Anonymous
2026-07-19 07:53:03
(17 hours ago)
Bot / scanning and/or hacking attempts: GET /.env HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
tsZero
2026-07-19 06:25:22
(18 hours ago)
Scan example: path=/.git/config status=403
Hacking