๐บ๐ธ
TPI-Abuse
2026-07-28 04:07:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 00:07:41.932238 2026] [security2:error] [pid 2070707:tid 2070707] [client 34.244.115.78:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maptshk.365soft.top"] [uri "/.git/config"] [unique_id "amgrDTXvxdey0xjC1kIS5wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-28 02:02:54
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:03:19
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-26.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 13:03:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:03:08.236228 2026] [security2:error] [pid 190426:tid 190426] [client 34.244.115.78:52482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matrixpercussiontrio.com"] [uri "/.git/config"] [unique_id "amdXDLs_jW1xP_TD6Zu-MgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mravb
2026-07-27 12:50:40
(2 days ago)
34.244.115.78 - - [27/Jul/2026:15:50:39 +0300] "GET /.git/config HTTP/1.1" 404 145 "-" "Mozilla/5.0 ...
show more
34.244.115.78 - - [27/Jul/2026:15:50:39 +0300] "GET /.git/config HTTP/1.1" 404 145 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฉ๐ช
Starburst SysOp Team
2026-07-27 12:11:11
(2 days ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-nue6-2)
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-07-27 04:33:37
(2 days ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2026-07-27 01:32:10
(3 days ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 01:25:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 21:25:42.311796 2026] [security2:error] [pid 1339587:tid 1339613] [client 34.244.115.78:44534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "henrisphoto.robertdanielsllc.com"] [uri "/.git/config"] [unique_id "amazluuXS-yUTlWwl-beVwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-27 01:19:32
(3 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking
Anonymous
2026-07-25 17:58:24
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.244.115.78 (IE/Ireland/ec2-34-244-11 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.244.115.78 (IE/Ireland/ec2-34-244-115-78.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
๐ฉ๐ช
DocNetzwerk
2026-07-25 17:05:09
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.244.115.78 (IE/Ireland/ec2-34-244-11 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.244.115.78 (IE/Ireland/ec2-34-244-115-78.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
Anonymous
2026-07-25 15:33:53
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ซ๐ท
dynamix
2026-07-25 14:44:01
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:54:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.115.78 (ec2-34-244-115-78.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:54:23.092021 2026] [security2:error] [pid 2547653:tid 2547670] [client 34.244.115.78:33176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.agrigrailtechnologies.com"] [uri "/.git/config"] [unique_id "amTAD9UA3zOxWWI_7FqFMwAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack