πΊπΈ
TPI-Abuse
2026-07-28 10:13:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:13:29.693736 2026] [security2:error] [pid 860561:tid 860561] [client 16.54.223.69:47374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cocinasintegralesjp.com.spyasociados.com"] [uri "/.git/config"] [unique_id "amiAyY1GmBohQUoIw2LQlQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-07-28 10:00:09
(10 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-28 02:22:05
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 22:22:00.105395 2026] [security2:error] [pid 32512:tid 32512] [client 16.54.223.69:59884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cnphilos.bridgital.com"] [uri "/.git/config"] [unique_id "amgSSLa3mTHaQD7VksjE_AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
DocNetzwerk
2026-07-27 13:41:52
(1 day ago)
16.54.223.69 (CA/Canada/ec2-16-54-223-69.ca-central-1.compute.amazonaws.com), more than 7 Apache 403 ...
show more
16.54.223.69 (CA/Canada/ec2-16-54-223-69.ca-central-1.compute.amazonaws.com), more than 7 Apache 403 hits
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 13:38:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:38:06.139690 2026] [security2:error] [pid 386149:tid 386149] [client 16.54.223.69:49714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cs.cswiki.us"] [uri "/.git/config"] [unique_id "amdfPiGcHCptlj7awbTfcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 12:14:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.com ...
show more
(mod_security) mod_security (id:210492) triggered by 16.54.223.69 (ec2-16-54-223-69.ca-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:14:41.003173 2026] [security2:error] [pid 129100:tid 129100] [client 16.54.223.69:46352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crystalvisionsart.benshermanguitar.com"] [uri "/.git/config"] [unique_id "amdLsSE61hAf-ZlWr1Kp9wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
IndigoRidge
2026-07-27 06:41:53
(1 day ago)
16.54.223.69 - - [27/Jul/2026:02:41:51 -0400] "GET /.git/config HTTP/1.0" 404 4854 "-" "Mozilla/5.0 ...
show more
16.54.223.69 - - [27/Jul/2026:02:41:51 -0400] "GET /.git/config HTTP/1.0" 404 4854 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
16.54.223.69 - - [27/Jul/2026:02:41:51 -0400] "GET /.env HTTP/1.0" 500 5197 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
16.54.223.69 - - [27/Jul/2026:02:41:52 -0400] "GET /app/.env HTTP/1.0" 404 4854 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-07-27 06:19:27
(1 day ago)
(caddyscan) Scanner path probe from 16.54.223.69 (CA/Canada/ec2-16-54-223-69.ca-central-1.compute.am ...
show more
(caddyscan) Scanner path probe from 16.54.223.69 (CA/Canada/ec2-16-54-223-69.ca-central-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 16.54.223.69 - - [27/Jul/2026:06:19:26 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 16.54.223.69 - - [27/Jul/2026:06:19:26 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 16.54.223.69 - - [27/Jul/2026:06:19:26 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 16.54.223.69 - - [27/Jul/2026:06:19:26 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 16.54.223.69 - - [27/Jul/2026:06:19:26 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
πΊπΈ
mnsf
2026-07-26 03:05:35
(2 days ago)
Too many Status 40X (21)
Scanning/Probing (21)
Brute-Force
Web App Attack