๐บ๐ธ
TPI-Abuse
2026-07-27 11:43:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:43:27.852361 2026] [security2:error] [pid 660291:tid 660291] [client 154.58.229.12:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsfwmanager.com"] [uri "/.git/config"] [unique_id "amdEX1ilxOzwbCCIJ-mt_wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:47:26
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:47:17.897065 2026] [security2:error] [pid 431155:tid 431155] [client 154.58.229.12:38600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosurephotography.com"] [uri "/.git/config"] [unique_id "amc3NWiPjIxHOj_G5USZRwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:56:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:56:04.762404 2026] [security2:error] [pid 14053:tid 14053] [client 154.58.229.12:32768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pseudo.space"] [uri "/.env"] [unique_id "amcrNLM1TIFwU49uRB4GZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 09:48:56
(5 hours ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:30:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 154.58.229.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:30:53.316366 2026] [security2:error] [pid 57959:tid 57959] [client 154.58.229.12:51126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "melton.space"] [uri "/.env"] [unique_id "amclTfeDpJULZp4MDmYM9AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
lindi
2026-07-27 09:22:39
(6 hours ago)
trying to access .env file
...
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-07-27 08:45:00
(6 hours ago)
(y3) Failed access -byebye- from 154.58.229.12 (US/United States/-): (CF_ENABLE)
Hacking
๐ณ๐ฑ
ByeByte API
2026-07-27 08:23:19
(7 hours ago)
byebyte.space auth: GET /.git/HEAD at 2026-07-27T08:23:19Z. Honeypot path hit; firewall auto-banned ...
show more
byebyte.space auth: GET /.git/HEAD at 2026-07-27T08:23:19Z. Honeypot path hit; firewall auto-banned the IP for 24h. UA: 'Mozilla/5.0 (compatible; bingbot/2.0; +http://www.bing.com/bingbot.htm)'. Accept-Encoding: 'gzip, br'. Country (CF): US. TLS info: {"scheme":"https"}.
show less
Web App Attack
Port Scan
Anonymous
2026-07-27 06:42:15
(8 hours ago)
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET / HTTP/1.1" 403 124 "-" "CCBot/2.0 (https://comm ...
show more
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET / HTTP/1.1" 403 124 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET /.well-known/security.txt HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET /.env.local HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET /.env.bak HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; ClaudeBot/1.0; [email protected] )"
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET /.env.staging HTTP/1.1" 404 440 "-" "Mozilla/5.0 (compatible; Google-CloudVertexBot; +https://cloud.google.com/vertex-ai-bot)"
154.58.229.12 - - [27/Jul/2026:08:42:14 +0200] "GET /.env.staging HTTP/1.1" 404 244 "-" "Mozilla/5.0 (compatible; Google-CloudVertexBot; +https://cloud.google.com/vertex-ai-bot)"
154.58.229.12 - - [27/Ju
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-27 06:38:01
(8 hours ago)
154.58.229.12 - - [27/Jul/2026:08:38:00 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
154.58.229.12 - - [27/Jul/2026:08:38:00 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/bot)"
...
show less
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-27 06:00:00
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-07-26 23:40:21
(15 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-26 22:46:02
(16 hours ago)
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /app/.env HTTP/1.1, GET /.env.old HTTP/1 ...
show more
Bot / scanning and/or hacking attempts: GET / HTTP/1.1, GET /app/.env HTTP/1.1, GET /.env.old HTTP/1.1
show less
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-07-26 22:45:10
(16 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-07-26 22:00:15
(17 hours ago)
Auto-ban: >3000 req/min op 2026-07-26
Web App Attack
SSH
Hacking