πΊπΈ
TPI-Abuse
2026-07-27 13:34:31
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:34:25.039728 2026] [security2:error] [pid 505122:tid 505122] [client 3.140.194.133:43996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.globalpackets.net"] [uri "/.git/config"] [unique_id "amdeYUF8GgahKG2NyriFAwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Bedios GmbH
2026-07-27 02:15:36
(19 hours ago)
Login credentials theft attempt
Hacking
πΊπΈ
TPI-Abuse
2026-07-26 22:57:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 18:57:43.928218 2026] [security2:error] [pid 14587:tid 14606] [client 3.140.194.133:51854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bobchaos.com"] [uri "/.git/config"] [unique_id "amaQ5-KkGj1JA-dOM7SPpQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-26 01:05:02
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-25 11:14:48
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 10:20:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.140.194.133 (ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:19:56.542797 2026] [security2:error] [pid 1289367:tid 1289367] [client 3.140.194.133:44996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gardnercastle.com"] [uri "/.git/config"] [unique_id "amSNzJj5WGQQsJpPhAW3AwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wteiken
2026-07-25 01:33:22
(2 days ago)
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:21 -0400] "GET /.git/config HTTP/1.1" ...
show more
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:21 -0400] "GET /.git/config HTTP/1.1" 404 562 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:22 -0400] "GET /.env HTTP/1.1" 404 562 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:22 -0400] "GET /.env.local HTTP/1.1" 404 562 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:22 -0400] "GET /.env.production HTTP/1.1" 404 562 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:36662 - - [24/Jul/2026:21:33:22 -0400] "GET /.env.staging HTTP/1.1" 404 562 "-" "Mozilla/5.0 (X11; Linux x8
...
show less
Web App Attack
π¬π§
Aetherweb Ark
2026-07-24 18:32:14
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 3.140.194.133 (US/United States/ec2-3-140-194-1 ...
show more
(mod_security) mod_security (id:949110) triggered by 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.compute.amazonaws.com): N in the last X secs
show less
Web App Attack
π©πͺ
R.G.
2026-07-24 18:21:22
(3 days ago)
(ScanningForFiles) Scanning for files triggerd 3.140.194.133 (US/United States/ec2-3-140-194-133.us- ...
show more
(ScanningForFiles) Scanning for files triggerd 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 10 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-07-24 17:24:01
(3 days ago)
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.comp ...
show more
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:17:23:59 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:17:23:59 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:17:23:59 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:17:23:59 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:17:23:59 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 16:15:00
(3 days ago)
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.comp ...
show more
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:16:14:58 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:16:14:58 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:16:14:58 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:16:14:58 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:16:14:58 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
π·π΄
iulianh
2026-07-24 15:02:59
(3 days ago)
80,443
Brute-Force
SSH
Anonymous
2026-07-24 14:08:24
(3 days ago)
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.comp ...
show more
(caddyscan) Scanner path probe from 3.140.194.133 (US/United States/ec2-3-140-194-133.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:14:08:24 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:14:08:24 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:14:08:24 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:14:08:24 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.140.194.133 - - [24/Jul/2026:14:08:24 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
πΊπΈ
wteiken
2026-07-24 04:15:13
(3 days ago)
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:11 -0400] "GET /.git/config HTTP/1.1" ...
show more
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:11 -0400] "GET /.git/config HTTP/1.1" 404 562 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:12 -0400] "GET /.env HTTP/1.1" 404 562 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:12 -0400] "GET /.env.local HTTP/1.1" 404 562 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:12 -0400] "GET /.env.production HTTP/1.1" 404 562 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.net:443 3.140.194.133:39734 - - [24/Jul/2026:00:15:12 -0400] "GET /.env.staging HTTP/1.1"
...
show less
Web App Attack
π«π·
conseilgouz
2021-02-24 02:38:21
(5 years ago)
mue-0 : Trying access unauthorized files=>/images/jdownloads/screenshots/update.php()
Hacking