๐ฉ๐ช
DocNetzwerk
2026-07-27 11:38:27
(55 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 16.59.25.243 (US/United States/ec2-16-5 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 16.59.25.243 (US/United States/ec2-16-59-25-243.us-east-2.compute.amazonaws.com)
show less
SQL Injection
๐ณ๐ฑ
Site.eu
2026-07-27 10:09:59
(2 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-07-27 09:39:50
(2 hours ago)
(caddyscan) Scanner path probe from 16.59.25.243 (US/United States/ec2-16-59-25-243.us-east-2.comput ...
show more
(caddyscan) Scanner path probe from 16.59.25.243 (US/United States/ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 16.59.25.243 - - [27/Jul/2026:09:39:48 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 16.59.25.243 - - [27/Jul/2026:09:39:48 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 16.59.25.243 - - [27/Jul/2026:09:39:48 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 16.59.25.243 - - [27/Jul/2026:09:39:48 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 16.59.25.243 - - [27/Jul/2026:09:39:48 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 09:14:50
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:14:42.138164 2026] [security2:error] [pid 1551380:tid 1551380] [client 16.59.25.243:50440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dogdom.gulftelecom.com"] [uri "/.git/config"] [unique_id "amchgkPnRr30CYbGrxMUEgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:43:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:43:17.318144 2026] [security2:error] [pid 30121:tid 30121] [client 16.59.25.243:50642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dodosdiscuss.flyingdodostudio.com"] [uri "/.git/config"] [unique_id "amcMFcVsDfEmw5sYnSCxEgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 06:48:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:48:32.816334 2026] [security2:error] [pid 3470760:tid 3470760] [client 16.59.25.243:48522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.documents.progressivefileshare.org"] [uri "/.git/config"] [unique_id "amb_QNR1IYDkonINJzIw_gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:10:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:10:33.901572 2026] [security2:error] [pid 1919053:tid 1919061] [client 16.59.25.243:34332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doctoratedegree.org.aafm.us"] [uri "/.git/config"] [unique_id "amboSe2oa-MZ6LVjXdet0QAAAYA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 10:57:54
(1 day ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.e-anastasiadis.gr; logs=/var/log/httpd/domains/e-anastas ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.e-anastasiadis.gr; logs=/var/log/httpd/domains/e-anastasiadis.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-26 06:38:41
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
grassau.com
2026-07-26 06:37:05
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 16.59.25.243 (US/United States/Ohio/Col ...
show more
(mod_security) mod_security triggered on hostname [redacted] 16.59.25.243 (US/United States/Ohio/Columbus/ec2-16-59-25-243.us-east-2.compute.amazonaws.com)
show less
SQL Injection
๐ช๐ธ
robotstxt
2026-07-26 02:54:05
(1 day ago)
16.59.25.243 - - [26/Jul/2026:02:53:25 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 15631 "-" "Mozill ...
show more
16.59.25.243 - - [26/Jul/2026:02:53:25 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 15631 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:53:26 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 15631 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:53:26 +0000] "GET /webmail/phpinfo.php HTTP/1.1" 404 15631 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:53:27 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 15657 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:53:27 +0000] "GET /webmail/phpinfo.php HTTP/1.1" 4
...
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-07-26 02:21:46
(1 day ago)
16.59.25.243 - - [26/Jul/2026:02:21:16 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5 ...
show more
16.59.25.243 - - [26/Jul/2026:02:21:16 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:21:17 +0000] "GET /webmail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:21:18 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:21:20 +0000] "GET /webmail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="16.59.25.243"
16.59.25.243 - - [26/Jul/2026:02:21:21 +0000] "GET /mail/phpinfo.php HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Windows NT 10.0; W
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 21:59:55
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 02:38:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 16.59.25.243 (ec2-16-59-25-243.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:38:30.355545 2026] [security2:error] [pid 29426:tid 29426] [client 16.59.25.243:58196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.datingwomen-101.onlyincanada-eh.com"] [uri "/.git/config"] [unique_id "amQhpgnWVHQhby8LFJi4IAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-25 01:50:15
(2 days ago)
Excessive 404/403 errors
Brute-Force