๐บ๐ธ
TPI-Abuse
2026-10-02 13:51:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:51:03.102878 2026] [security2:error] [pid 17421:tid 17421] [client 184.193.215.139:21008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hope4elsalvador.org"] [uri "/.env.save"] [unique_id "ar-2x4DAheMbHS2C9GMY_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 06:55:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 02:55:05.669848 2026] [security2:error] [pid 27041:tid 27041] [client 184.193.215.139:23744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ospreylake.org"] [uri "/wp-config.php.swp"] [unique_id "ar9VSQSo5LbdfQrwpoYMzwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-09-29 21:43:59
(6 days ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: DomainAtlas-Ingest/0.1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 19:53:14
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:53:09.516124 2026] [security2:error] [pid 30057:tid 30057] [client 184.193.215.139:18445] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abneyfoundation.org"] [uri "/wp-config.php.bak.php"] [unique_id "arwXJYYN78DapF33ZjA_eAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 10:59:27
(1 week ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-09-28 03:10:48
(1 week ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (compatible; ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (compatible; SiteSafetyInventory/4.0; +responsible-disclosure) | 2026-09-28 03:10 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-25 15:02:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 11:02:38.528749 2026] [security2:error] [pid 18473:tid 18473] [client 184.193.215.139:45518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "h-vpastoralcharge.org"] [uri "/config/.env"] [unique_id "araNDlSgTWPSOttBn_5UEgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:28:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:27:59.785600 2026] [security2:error] [pid 374:tid 374] [client 184.193.215.139:46536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earlyfordv8crrg10.com"] [uri "/.env.bak"] [unique_id "arRuj8gglrww2wFZEqJJCAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:21:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:21:07.353317 2026] [security2:error] [pid 19062:tid 19062] [client 184.193.215.139:3576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacpool.com"] [uri "/.env.development"] [unique_id "arLjM7_OVK2TFiJeHBTH8AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:01:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:00:58.082686 2026] [security2:error] [pid 23490:tid 23490] [client 184.193.215.139:58462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.assec.org"] [uri "/.env.production"] [unique_id "arLQajir89pxUgtKuu-r5AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
demonsword
2026-09-19 09:39:55
(2 weeks ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: api.ipify.org:443
show less
Open Proxy
Port Scan
๐ฏ๐ต
Execoop
2026-09-19 02:50:58
(2 weeks ago)
API LLMjacking (Ollama) (observed): 4 HTTP, 3s; attempted cryptomining; Ollama: /v1/chat/completions
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 13:25:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1. ...
show more
(mod_security) mod_security (id:210492) triggered by 184.193.215.139 (ec2-184-193-215-139.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 09:25:31.474688 2026] [security2:error] [pid 22330:tid 22330] [client 184.193.215.139:6186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/wp-config.php.bak"] [unique_id "aq07y1NuGJNtezXAvMAV6AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-17 12:01:10
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 15:50:13
(2 weeks ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: HEAD | path: / | 2026-09-16 15:50 UTC
show less
Bad Web Bot