๐ฌ๐ง
Steve
2026-07-27 12:49:33
(18 hours ago)
SQL Injection Attempts
Brute-Force
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-27 04:58:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:58:40.842723 2026] [security2:error] [pid 22148:tid 22180] [client 15.134.208.115:56358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.transiit.org"] [uri "/.git/config"] [unique_id "amblgIIdkq56TzHGTksp0QAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-26 23:57:57
(1 day ago)
15.134.208.115 - - [27/Jul/2026:01:57:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
15.134.208.115 - - [27/Jul/2026:01:57:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-25 15:11:56
(2 days ago)
[osotir.org] httpd-config-scan: sites=www.eopb.gr; logs=/var/log/httpd/domains/eopb.gr.log; samples= ...
show more
[osotir.org] httpd-config-scan: sites=www.eopb.gr; logs=/var/log/httpd/domains/eopb.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-25 14:14:58
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:15:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:15:51.514151 2026] [security2:error] [pid 3410757:tid 3410757] [client 15.134.208.115:59134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicureankids.com"] [uri "/.git/config"] [unique_id "amMtRwLWss2hlzqAori1oAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 07:27:20
(3 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐จ๐ญ
leo1305
2026-07-24 05:50:46
(4 days ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-24 05:13:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.208.115 (ec2-15-134-208-115.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:13:24.090874 2026] [security2:error] [pid 4024632:tid 4024632] [client 15.134.208.115:36364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epetsure.co"] [uri "/.git/config"] [unique_id "amL0dLo9qqmumfNo11O77QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 03:44:45
(4 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking