๐บ๐ธ
TPI-Abuse
2026-07-18 06:55:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 02:55:47.118462 2026] [security2:error] [pid 17348:tid 17348] [client 16.184.51.162:36784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.shopping.pswebsite.com"] [uri "/.git/config"] [unique_id "alsjcyoUbmGtnBXU1XOuyAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-18 04:05:35
(4 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-18 03:16:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 23:16:29.710130 2026] [security2:error] [pid 10339:tid 10339] [client 16.184.51.162:45082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.shop.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "alrwDReNQKwQ4UpA0qeTrgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:05:25
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 11:24:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:24:40.794140 2026] [security2:error] [pid 22171:tid 22171] [client 16.184.51.162:38374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test-site.angelaridgwaydressage.com"] [uri "/.git/config"] [unique_id "aloQ-CKY3iBaC5y35fHn3QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 09:50:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:49:59.179657 2026] [security2:error] [pid 12712:tid 12763] [client 16.184.51.162:35970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.testproperty.pref-realestate.com"] [uri "/.git/config"] [unique_id "aln6x2C05SpjsVMin89ZcgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:29:05
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:29:01.436263 2026] [security2:error] [pid 514102:tid 514102] [client 16.184.51.162:33406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.testo.kmelson.com"] [uri "/.git/config"] [unique_id "alnnzdidtliUGSqkWO70RwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 06:56:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 02:56:39.874910 2026] [security2:error] [pid 20600:tid 20600] [client 16.184.51.162:44058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.mathewyoung.com"] [uri "/.git/config"] [unique_id "alnSJ9GA5wfSeJKi5vXbuwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-17 04:41:08
(5 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-17 03:01:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 23:01:50.471746 2026] [security2:error] [pid 173667:tid 173667] [client 16.184.51.162:53892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.grimone.com"] [uri "/.git/config"] [unique_id "almbHsTDwECRz1xCYFabkwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-17 02:50:05
(5 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 02:33:16
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 22:33:11.318824 2026] [security2:error] [pid 149992:tid 149992] [client 16.184.51.162:35872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.fritsknuf.com"] [uri "/.git/config"] [unique_id "almUZ87copsxhacBKneDuwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 01:05:02
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2 ...
show more
(mod_security) mod_security (id:210492) triggered by 16.184.51.162 (ec2-16-184-51-162.ap-northeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 21:04:57.085007 2026] [security2:error] [pid 13491:tid 13491] [client 16.184.51.162:44120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.empoweruohio.org"] [uri "/.git/config"] [unique_id "all_uQfnMXmljlTRyiEfzgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-16 22:04:23
(5 days ago)
Auto-ban: >3000 req/min op 2026-07-16
Web App Attack
SSH
Hacking
๐ช๐ธ
pipeline.es
2026-07-16 16:41:20
(6 days ago)
Web scanning / probing for vulnerable paths | URL: /crm/.env | Evidence: travelplanet.pt 16.184.51.1 ...
show more
Web scanning / probing for vulnerable paths | URL: /crm/.env | Evidence: travelplanet.pt 16.184.51.162 - - [16/Jul/2026:18:37:33 +0200] \"GET /crm/.env HTTP/1.1\" 404 20386 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=KR | ASN: AMAZON-02 | Country: KR
show less
Port Scan
Web App Attack