๐บ๐ธ
TPI-Abuse
2026-07-27 15:45:24
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:45:18.594736 2026] [security2:error] [pid 1254576:tid 1254576] [client 13.238.161.48:45584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fanarch.xyz"] [uri "/.git/config"] [unique_id "amd9DjTGFG6Nkmp0VebPBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-27 13:30:27
(21 hours ago)
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: familytour.tur.br ...
show more
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: familytour.tur.br 13.238.161.48 - - [27/Jul/2026:15:29:32 +0200] \"GET /notifications/.env HTTP/1.1\" 404 17937 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=AU | ASN: AMAZON-02 | Country: AU
show less
Port Scan
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-27 12:20:53
(22 hours ago)
13.238.161.48 - - [27/Jul/2026:15:20:50 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 ...
show more
13.238.161.48 - - [27/Jul/2026:15:20:50 +0300] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
13.238.161.48 - - [27/Jul/2026:15:20:52 +0300] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:53:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:52:56.255762 2026] [security2:error] [pid 159698:tid 159698] [client 13.238.161.48:38558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "family.amgtr.com"] [uri "/.git/config"] [unique_id "amcqePl18FvrgEE_4QL4yQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-07-25 17:00:06
(2 days ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-25 12:29:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 08:29:20.550781 2026] [security2:error] [pid 15969:tid 15969] [client 13.238.161.48:33034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "magazine.angelabcomics.com"] [uri "/.git/config"] [unique_id "amSsIJb9E8dWkq_9EG3e2wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:01:03
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ฉ๐ช
LRob
2026-07-24 20:46:53
(3 days ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5. ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 13:06:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 13.238.161.48 (ec2-13-238-161-48.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:05:58.154414 2026] [security2:error] [pid 4143989:tid 4143989] [client 13.238.161.48:45658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lunchtimers.org"] [uri "/.git/config"] [unique_id "amNjNjVmSvlPILO3IGqEAQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 10:45:03
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-07-24 06:30:29
(4 days ago)
| [Dangerous/Australia] Aggressive IP 13.238.161.48 (~30 hits). Type: DoS Defender- Web server 400 e ...
show more
| [Dangerous/Australia] Aggressive IP 13.238.161.48 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection