πΊπΈ
Matthew Ping
2026-07-27 19:45:01
(16 hours ago)
ModSecurity rule 949110 triggered on clearedge3d. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
π©πͺ
Petros Stefanakis
2026-07-27 16:27:40
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 18.191.56.164 (US/United States/ec2-18- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 18.191.56.164 (US/United States/ec2-18-191-56-164.us-east-2.compute.amazonaws.com)
show less
SQL Injection
π©πͺ
maxpower
2026-07-27 15:04:50
(20 hours ago)
(PERMBLOCK) 18.191.56.164 (US/United States/ec2-18-191-56-164.us-east-2.compute.amazonaws.com) has h ...
show more
(PERMBLOCK) 18.191.56.164 (US/United States/ec2-18-191-56-164.us-east-2.compute.amazonaws.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-27 14:23:45
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 10:23:39.269925 2026] [security2:error] [pid 3716594:tid 3716594] [client 18.191.56.164:53442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circlethreefl.com"] [uri "/.git/config"] [unique_id "amdp639dzta7YLNbrxNBUgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 13:59:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:58:53.095390 2026] [security2:error] [pid 3886598:tid 3886598] [client 18.191.56.164:41770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circleinthesquare.org"] [uri "/.git/config"] [unique_id "amdkHVUA3j9FqeO3ds7JPgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 13:26:23
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:26:18.491099 2026] [security2:error] [pid 676468:tid 676468] [client 18.191.56.164:47418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circle-h-growers.com"] [uri "/.git/config"] [unique_id "amdceiRWqKlq-zLL7BBjhAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-07-27 13:21:53
(22 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 12:45:12
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:44:59.277702 2026] [security2:error] [pid 3425236:tid 3425236] [client 18.191.56.164:34962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ciptaconindotara.com"] [uri "/.git/config"] [unique_id "amdSy0c2Kr7PKvJSMKdY1QAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 11:10:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:10:05.224293 2026] [security2:error] [pid 722597:tid 722597] [client 18.191.56.164:59936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cipcug.org"] [uri "/.git/config"] [unique_id "amc8jQoU5XYE-Cgg5lKPvwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 10:08:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:08:44.845718 2026] [security2:error] [pid 3694861:tid 3694861] [client 18.191.56.164:36154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cintiaparral.com"] [uri "/.git/config"] [unique_id "amcuLNPP3cdhOZkSHdakgwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-07-27 10:07:31
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-27 08:21:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 18.191.56.164 (ec2-18-191-56-164.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:21:21.771222 2026] [security2:error] [pid 4100959:tid 4100959] [client 18.191.56.164:48452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cinesonline.com"] [uri "/.git/config"] [unique_id "amcVAZLX6BlxNueAQkUaiwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 05:05:33
(1 day ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (41/60 min)'; Requests=41
Port Scan
π³π±
homeshowdomain.nl
2026-07-26 21:59:53
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-25.
show less
Web App Attack
SSH
Hacking
π«π·
Octopuce
2026-07-26 08:04:44
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack