๐บ๐ธ
MPL
2026-06-04 16:21:03
(2 weeks ago)
tcp port scan (16 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-04 15:50:55
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:50:49.661336 2026] [security2:error] [pid 7405:tid 7405] [client 52.159.247.224:55666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.181"] [uri "/.git/HEAD"] [unique_id "aiGe2UbdSM5e97cDjyKMKwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 15:17:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:17:08.836454 2026] [security2:error] [pid 15955:tid 15955] [client 52.159.247.224:55207] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.161"] [uri "/.git/HEAD"] [unique_id "aiGW9DxOQoFbJRUBW0_RFAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
AutosOnShow
2026-06-04 14:45:05
(2 weeks ago)
blocked for webapp attack | path requested: /.env | seen at 2026-06-04 14:44:28.423 |
Web App Attack
๐ต๐ฑ
nfsec.pl
2026-06-04 13:22:21
(2 weeks ago)
Detected: TCP scan on port: 8080 with flags: SYN
Port Scan
๐บ๐ธ
RAP
2026-06-04 13:11:41
(2 weeks ago)
2026-06-04 13:11:41 UTC Unauthorized activity to TCP port 8080. Web App
Port Scan
Web App Attack
๐ช๐ธ
yvoictra
2026-06-04 12:19:45
(2 weeks ago)
52.159.247.224 - - [04/Jun/2026:14:19:35 +0200] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 ( ...
show more
52.159.247.224 - - [04/Jun/2026:14:19:35 +0200] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.159.247.224 - - [04/Jun/2026:14:19:38 +0200] "GET /.git/config HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15"
52.159.247.224 - - [04/Jun/2026:14:19:40 +0200] "GET /.env HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
52.159.247.224 - - [04/Jun/2026:14:19:42 +0200] "GET /.env.local HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
52.159.247.224 - - [04/Jun/2026:14:19:45 +0200] "GET /.env.production HTTP/1.1" 404 134 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-04 12:01:39
(2 weeks ago)
Tried our host z.
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-04 11:55:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:55:37.341941 2026] [security2:error] [pid 3046:tid 3046] [client 52.159.247.224:55941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.9"] [uri "/.git/HEAD"] [unique_id "aiFnucFb74mFe2SxxISvygAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-06-02 06:40:46
(3 weeks ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐ฎ๐ณ
Mr.Singh
2026-06-02 06:31:09
(3 weeks ago)
NFT blocked 52.159.247.224 after 4 rejections on 02-Jun-2026.
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 05:53:24
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:53:20.720937 2026] [security2:error] [pid 32458:tid 32458] [client 52.159.247.224:58583] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.167"] [uri "/.env.local"] [unique_id "ah5v0IFiBpVh6BuemReSkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TJTheSpy
2026-06-02 05:26:09
(3 weeks ago)
52.159.247.224 - - [02/Jun/2026:05:25:46 +0000] "GET /.git/HEAD HTTP/1.1" 404 2208 "-" "Mozilla/5.0 ...
show more
52.159.247.224 - - [02/Jun/2026:05:25:46 +0000] "GET /.git/HEAD HTTP/1.1" 404 2208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.159.247.224 - - [02/Jun/2026:05:25:48 +0000] "GET /.git/config HTTP/1.1" 404 2208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.159.247.224 - - [02/Jun/2026:05:25:55 +0000] "GET /.env.production HTTP/1.1" 404 2208 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
52.159.247.224 - - [02/Jun/2026:05:26:06 +0000] "GET /.aws/credentials HTTP/1.1" 404 2208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:125.0) Gecko/20100101 Firefox/125.0"
52.159.247.224 - - [02/Jun/2026:05:26:08 +0000] "GET /config/database.yml HTTP/1.1" 404 2208 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-02 04:27:15
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 52.159.247.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:27:11.084038 2026] [security2:error] [pid 16158:tid 16158] [client 52.159.247.224:58965] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.244"] [uri "/.git/config"] [unique_id "ah5bn5sJSp1u-WpJxfnMogAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ITSNF
2026-06-02 04:20:03
(3 weeks ago)
Blocked by os-abuseipdb; 8 hits, proto=tcp, ports=2082,2083,2086,2087,443,80,8080,8443
Port Scan
Hacking