๐ซ๐ท
dynamix
2025-09-08 09:54:09
(11 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-08 04:24:40
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 08 00:24:35.337201 2025] [security2:error] [pid 15696:tid 15696] [client 13.201.50.212:41024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zheunda.com.greighhouse.com"] [uri "/.env"] [unique_id "aL5agz1ri8Wxsr0TtacATAAAAAo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2025-09-07 19:01:29
(11 months ago)
20 attempts against mh-misbehave-ban on ec102955
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2025-09-07 16:03:20
(11 months ago)
20 attempts against mh-misbehave-ban on neon
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
zorrigas
2025-09-07 12:51:30
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (IN/India/ec2-13-201-50-212.ap-so ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (IN/India/ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 5 in the last 3600 secs
show less
Brute-Force
๐ท๐บ
andrey volobuev
2025-09-07 12:41:35
(11 months ago)
[07/Sep/2025:15:41:29 +0300] - 404 404 - GET http zerotier.bebesh.ru "/.env" [Client 13.201.50.212] ...
show more
[07/Sep/2025:15:41:29 +0300] - 404 404 - GET http zerotier.bebesh.ru "/.env" [Client 13.201.50.212] [Length 714] [Gzip -] [Sent-to 192.168.1.172] "Mozilla/5.0 (Windows; U; MSIE 7.0; Linux x86_64; .NET CLR 3.2.4069; X11)" "https://www.google.com/"
[07/Sep/2025:15:41:29 +0300] - 404 404 - GET http zerotier.bebesh.ru "/.remote" [Client 13.201.50.212] [Length 714] [Gzip -] [Sent-to 192.168.1.172] "Mozilla/5.0 (Windows; U; MSIE 7.0; Linux x86_64; .NET CLR 3.2.4069; X11)" "https://www.google.com/"
[07/Sep/2025:15:41:30 +0300] - 404 404 - GET http zerotier.bebesh.ru "/.local" [Client 13.201.50.212] [Length 714] [Gzip -] [Sent-to 192.168.1.172] "Mozilla/5.0 (Windows; U; MSIE 7.0; Linux x86_64; .NET CLR 3.2.4069; X11)" "https://www.google.com/"
[07/Sep/2025:15:41:30 +0300] - 404 404 - GET http zerotier.bebesh.ru "/.production" [Client 13.201.50.212] [Length 714] [Gzip -] [Sent-to 192.168.1.172] "Mozilla/5.0 (Windows; U; MSIE 7.0; Linux x86_64; .NET CLR 3.2.4069; X11)" "https://www.google.com/"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2025-09-07 07:01:49
(11 months ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
NewWavesApp
2025-09-07 05:15:46
(11 months ago)
(mod_security) mod_security triggered on hostname [redacted] 13.201.50.212 (IN/India/ec2-13-201-50-2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 13.201.50.212 (IN/India/ec2-13-201-50-212.ap-south-1.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2025-09-07 04:18:37
(11 months ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 07 00:18:33.238289 2025] [security2:error] [pid 16456:tid 16456] [client 13.201.50.212:53592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roguetechink.com"] [uri "/.env"] [unique_id "aL0HmVZbonW555PwoqebNgAAAA0"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-09-07 04:06:56
(1 year ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 03:40:28
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:40:21.735945 2025] [security2:error] [pid 9801:tid 9816] [client 13.201.50.212:39504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rodela.com"] [uri "/.env"] [unique_id "aLz-pXgGnwQPlRTC1GEQiwAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 03:24:00
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 23:23:55.076310 2025] [security2:error] [pid 18116:tid 18116] [client 13.201.50.212:46200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocky-ridgeco.com"] [uri "/.env"] [unique_id "aLz6yyeAiFRaZLGp5hYNfQAAABQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-07 02:41:17
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 22:41:11.241216 2025] [security2:error] [pid 13452:tid 13452] [client 13.201.50.212:47174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockymtnfire.com"] [uri "/.env"] [unique_id "aLzwx0Db8fh2T02ejzhxRAAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2025-09-07 02:36:58
(1 year ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-09-07 02:20:11
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 13.201.50.212 (ec2-13-201-50-212.ap-south-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 06 22:20:04.823926 2025] [security2:error] [pid 16817:tid 16817] [client 13.201.50.212:59830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocksolidhomebuilders.com"] [uri "/.env"] [unique_id "aLzr1JVjgDhbW4UkN6KafgAAAAE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack