Anonymous
2026-07-25 17:54:07
(7 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-25 04:02:01
(21 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
Anonymous
2026-07-24 23:00:25
(1 day ago)
15.134.221.122 - - [25/Jul/2026:01:00:21 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macinto ...
show more
15.134.221.122 - - [25/Jul/2026:01:00:21 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
15.134.221.122 - - [25/Jul/2026:01:00:21 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
15.134.221.122 - - [25/Jul/2026:01:00:21 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
15.134.221.122 - - [25/Jul/2026:01:00:21 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
15.134.221.122 - - [25/Jul/2026:01:00:22 +0200] "GET /.git/config HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:01:40
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 19:30:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:30:02.659378 2026] [security2:error] [pid 2202560:tid 2202560] [client 15.134.221.122:43040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batfry.internetnameregistration.com"] [uri "/.git/config"] [unique_id "amO9Ojmtt0Jks8_gLjN_NQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 18:59:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:58:58.067014 2026] [security2:error] [pid 4155654:tid 4155654] [client 15.134.221.122:55308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batchovens.net.daveweisman.com"] [uri "/.git/config"] [unique_id "amO18p5K29NFcGtCcZjveQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:25:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:24:56.821410 2026] [security2:error] [pid 4052150:tid 4052150] [client 15.134.221.122:46862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bastardesign.va-designers.com"] [uri "/.git/config"] [unique_id "amOf6L6p-hpaGGv098kiQAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:48:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:48:48.945945 2026] [security2:error] [pid 460572:tid 460572] [client 15.134.221.122:50908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.basse.lahamradio.com"] [uri "/.git/config"] [unique_id "amOXcJrBTEXnf-0l1cVWCwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:46:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 15.134.221.122 (ec2-15-134-221-122.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:46:31.344422 2026] [security2:error] [pid 161665:tid 161665] [client 15.134.221.122:40234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.baseball.jpwatters.net"] [uri "/.git/config"] [unique_id "amNQl4FN3uyNLfOFictHHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 11:16:44
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
masterguru
2026-07-24 05:45:19
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-24 05:43:47
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking