๐บ๐ธ
TPI-Abuse
2026-07-28 00:04:33
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:04:29.309587 2026] [security2:error] [pid 1179126:tid 1179126] [client 3.142.252.223:39490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theopinionatedowl.com"] [uri "/.git/config"] [unique_id "amfyDeM-bgv-lznmv1LMIgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-27 21:33:43
(6 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 21:23:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 17:23:05.860167 2026] [security2:error] [pid 715720:tid 715720] [client 3.142.252.223:59852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenowhere-men.com"] [uri "/.git/config"] [unique_id "amfMOR7JUrPAa01rfZe2AQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 21:05:07
(7 hours ago)
(caddyscan) Scanner path probe from 3.142.252.223 (US/United States/ec2-3-142-252-223.us-east-2.comp ...
show more
(caddyscan) Scanner path probe from 3.142.252.223 (US/United States/ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 3.142.252.223 - - [27/Jul/2026:21:05:02 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 3.142.252.223 - - [27/Jul/2026:21:05:02 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 3.142.252.223 - - [27/Jul/2026:21:05:02 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 3.142.252.223 - - [27/Jul/2026:21:05:02 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 3.142.252.223 - - [27/Jul/2026:21:05:02 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 20:42:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:42:12.901505 2026] [security2:error] [pid 1745888:tid 1745888] [client 3.142.252.223:55474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenitecapsbluesband.craftcare.net"] [uri "/.git/config"] [unique_id "amfCpFvneXeUIa8X8x4U2AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 19:15:24
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:15:19.171524 2026] [security2:error] [pid 1857424:tid 1857424] [client 3.142.252.223:36752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theneighborswindow.com"] [uri "/.git/config"] [unique_id "ameuR_nkD8UqnjDb-ck6eQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:23:38
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 3.142.252.223 (ec2-3-142-252-223.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:23:35.415299 2026] [security2:error] [pid 9598:tid 9598] [client 3.142.252.223:52708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "themotelwest.com"] [uri "/.git/config"] [unique_id "ambrVyemfKqJ-Hpo-IEsQwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-26 02:14:42
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ฑ๐ป
garmtech.com
2026-07-25 01:37:34
(3 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-25 01:19:01
(3 days ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/app/.env
Web App Attack
๐จ๐ญ
zynex
2026-07-25 01:18:19
(3 days ago)
URL Probing: /server/.env
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-07-24 11:09:52
(3 days ago)
2026/07/24 13:09:21 [error] 100879#100879: *128297 open() "/home/user-data/www/default/mailer/.env" ...
show more
2026/07/24 13:09:21 [error] 100879#100879: *128297 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 3.142.252.223, server: autodiscover.optique-gravelines.fr, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.optique-gravelines.fr"
2026/07/24 13:09:21 [error] 100879#100879: *128297 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 3.142.252.223, server: autodiscover.optique-gravelines.fr, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.optique-gravelines.fr"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
Anonymous
2026-07-24 06:26:10
(3 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 05:15:04
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฆ๐บ
rubixstudios
2026-07-24 04:24:02
(4 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack