๐ซ๐ท
masterguru
2026-07-27 13:42:39
(4 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 13:03:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:02:57.826261 2026] [security2:error] [pid 1615685:tid 1615685] [client 108.131.157.72:38090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agreyhawkcampaign.net"] [uri "/.git/config"] [unique_id "amdXATdxUfB4tdM1q5zJRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:44:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:44:11.064312 2026] [security2:error] [pid 2318220:tid 2318324] [client 108.131.157.72:33066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agqo.org"] [uri "/.git/config"] [unique_id "amdEi7eiafzc66ZXNB0z3AAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-07-27 10:58:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (IE/Ireland/ec2-108-131-157-72.e ...
show more
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (IE/Ireland/ec2-108-131-157-72.eu-west-1.compute.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 10:41:36
(7 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฉ๐ช
LRob
2026-07-27 10:02:55
(8 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5. ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-07-27 09:29:13
(8 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 07:10:05
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:09:56.651756 2026] [security2:error] [pid 3287585:tid 3287585] [client 108.131.157.72:50414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agirlwithaguitar.com"] [uri "/.git/config"] [unique_id "amcERBt2yEA3MRm9gSv3XgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 04:30:39
(13 hours ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ญ
backslash
2026-07-27 04:18:00
(13 hours ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
๐ฉ๐ช
Petros Stefanakis
2026-07-27 04:12:09
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 108.131.157.72 (IE/Ireland/ec2-108-131- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 108.131.157.72 (IE/Ireland/ec2-108-131-157-72.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 21:59:52
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-25.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 08:41:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 108.131.157.72 (ec2-108-131-157-72.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 04:41:31.314406 2026] [security2:error] [pid 3920241:tid 3920241] [client 108.131.157.72:52388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alkymera.ahijado.org"] [uri "/.git/config"] [unique_id "amXIO5Xqlgjd2D12_Y05OAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 03:48:15
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/test/.env
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 21:59:06
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking