๐ฉ๐ช
kommunos
2026-08-27 18:29:27
(1 minute ago)
/v1/graphql
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 16:55:02
(1 hour ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-27 16:50:40
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
sefinek.net
2026-08-27 16:19:42
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/2 (GET) | Endpoint: /wp-config.php~ | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; MistralAI-User/1.0 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 15:25:11
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:24:59.095710 2026] [security2:error] [pid 21011:tid 21011] [client 44.223.36.252:38604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "socialstudiesforkids.com"] [uri "/.git/HEAD"] [unique_id "apBWyyw0gKpWs-690XX7YgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:29:11
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:29:04.692801 2026] [security2:error] [pid 13608:tid 13608] [client 44.223.36.252:40666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laecovillage.org"] [uri "/.git/HEAD"] [unique_id "apBJsN0Q8qnO8RFHIloNbQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-08-27 13:40:02
(4 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:47:52
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:47:47.941505 2026] [security2:error] [pid 28787:tid 28787] [client 44.223.36.252:56000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rodandreelpiercam.com|F|2"] [data ".rodandreelpiercam.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rodandreelpiercam.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rodandreelpiercam.com"] [unique_id "apAx87HOISpwMXxAJNuY1QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:12:43
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 44.223.36.252 (ec2-44-223-36-252.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:12:35.240444 2026] [security2:error] [pid 10741:tid 10741] [client 44.223.36.252:34356] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||megastorebuilders.info|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "megastorebuilders.info"] [uri "/rclone.conf"] [unique_id "apApszA4zIjgucg2UrLG4wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-08-27 12:10:45
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 44.223.36.252 (US/United States/ec2-44-223-36-2 ...
show more
(mod_security) mod_security (id:949110) triggered by 44.223.36.252 (US/United States/ec2-44-223-36-252.compute-1.amazonaws.com): N in the last X secs
show less
Web App Attack
๐ง๐ช
voormedia
2026-08-27 11:42:58
(6 hours ago)
Accessed trap at '/.aws/config'
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 11:05:24
(7 hours ago)
Abuse Detected (14)
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-27 10:46:30
(7 hours ago)
Web scanning / probing for vulnerable paths | URL: /.git-credentials | Evidence: novorumo.pt 44.223. ...
show more
Web scanning / probing for vulnerable paths | URL: /.git-credentials | Evidence: novorumo.pt 44.223.36.252 - - [27/Aug/2026:12:45:04 +0200] \"GET /.git-credentials HTTP/2.0\" 404 20895 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email]\" GEOIP_COUNTRY_CODE=US | ASN: AMAZON-AES | Country: US
show less
Port Scan
Web App Attack
Anonymous
2026-08-27 10:15:17
(8 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 10:02:51
(8 hours ago)
[27/Aug/2026:13:02:50 +0300] -- 44.223.36.252 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[27/Aug/2026:13:02:50 +0300] -- 44.223.36.252 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/HEAD HTTP/1.1
show less
Bad Web Bot
Web App Attack