๐บ๐ธ
TPI-Abuse
2026-07-27 05:16:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:16:11.177698 2026] [security2:error] [pid 3840844:tid 3840844] [client 3.253.36.24:35692] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mfleetservice.com"] [uri "/.git/config"] [unique_id "ambpm92AHCdWdYZ-E0scGwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
webadmin
2026-07-26 06:46:10
(1 day ago)
2026-07-26T08:46:02.677371+02:00 tytan mobile-sai-api[4129]: [error] client: 3.253.36.24 server: mob ...
show more
2026-07-26T08:46:02.677371+02:00 tytan mobile-sai-api[4129]: [error] client: 3.253.36.24 server: mobile.sai.pl, request: "POST", url: http://mobile.sai.pl/ [405]: Method Not Allowed
2026-07-26T08:46:03.688704+02:00 tytan mobile-sai-api[4129]: [error] client: 3.253.36.24 server: mobile.sai.pl, request: "POST", url: http://mobile.sai.pl/ [405]: Method Not Allowed
2026-07-26T08:46:06.214239+02:00 tytan mobile-sai-api[4129]: [error] client: 3.253.36.24 server: mobile.sai.pl, request: "POST", url: http://mobile.sai.pl/ [405]: Method Not Allowed
2026-07-26T08:46:09.389995+02:00 tytan mobile-sai-api[4129]: [error] client: 3.253.36.24 server: mobile.sai.pl, request: "GET", url: http://mobile.sai.pl/.git/config [404]: Not Found
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-07-26 03:22:29
(1 day ago)
Malware host detected by rbl.malware.expert. RBL lookup of 24.36.253.3.rbl.malware.expert succeeded ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 24.36.253.3.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-7)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 10:45:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:45:32.625305 2026] [security2:error] [pid 766479:tid 766485] [client 3.253.36.24:35278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "poeticdialogues.com"] [uri "/.git/config"] [unique_id "amNCTIGnyT19lJjew16eWAAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:49:10
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:49:02.363609 2026] [security2:error] [pid 3737209:tid 3737209] [client 3.253.36.24:38602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pocosfarm.com"] [uri "/.git/config"] [unique_id "amMm_mPdP6exttpW72DXGAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 07:10:54
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
netclix.gr
2026-07-24 06:23:29
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 3.253.36.24 (IE/Ireland/ec2-3-253-36-24 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.253.36.24 (IE/Ireland/ec2-3-253-36-24.eu-west-1.compute.amazonaws.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-24 06:07:26
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute. ...
show more
(mod_security) mod_security (id:210492) triggered by 3.253.36.24 (ec2-3-253-36-24.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:07:19.837848 2026] [security2:error] [pid 3113004:tid 3113004] [client 3.253.36.24:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pnp42.com"] [uri "/.git/config"] [unique_id "amMBF7nB-0GAHKS-sdAw0gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 04:20:03
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-24 03:27:27
(3 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐จ๐ญ
backslash
2026-04-14 09:51:01
(3 months ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
๐ฌ๐ง
mangomad
2022-11-18 17:28:41
(3 years ago)
Repeated Apache mod_security rule triggers
Brute-Force
Web App Attack