๐บ๐ธ
TPI-Abuse
2026-07-27 11:16:21
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:16:18.210608 2026] [security2:error] [pid 3169312:tid 3169312] [client 52.34.72.225:36832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nowthatscountry.tv"] [uri "/.git/config"] [unique_id "amc-AsH8XRjRA6Rz70-VsgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:21:45
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:21:41.024455 2026] [security2:error] [pid 3410867:tid 3410867] [client 52.34.72.225:51382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nowell.net"] [uri "/.git/config"] [unique_id "amcjJRzvaZ5RRlvIdge8JAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 07:54:10
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:54:02.608466 2026] [security2:error] [pid 3716256:tid 3716256] [client 52.34.72.225:51928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "now-app.space"] [uri "/.git/config"] [unique_id "amcOmhF2lXXNtA1JGYdnJAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-07-27 07:41:36
(23 hours ago)
52.34.72.225 - - [27/Jul/2026:09:41:32 +0200] "GET /job/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Win ...
show more
52.34.72.225 - - [27/Jul/2026:09:41:32 +0200] "GET /job/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.34.72.225 - - [27/Jul/2026:09:41:33 +0200] "GET /test/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.34.72.225 - - [27/Jul/2026:09:41:33 +0200] "GET /qa/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.34.72.225 - - [27/Jul/2026:09:41:33 +0200] "GET /preview/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.34.72.225 - - [27/Jul/2026:09:41:33 +0200] "GET /beta/.env HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
52.34.72.2
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-26 06:11:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:11:04.793179 2026] [security2:error] [pid 1608169:tid 1608169] [client 52.34.72.225:39076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oficial.gisur.com"] [uri "/.git/config"] [unique_id "amWk-LuDh1jKplfun8SSbgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:00:01
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-25
Web App Attack
SSH
Hacking
๐ซ๐ท
Octopuce
2026-07-24 09:47:50
(3 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฌ๐ง
Apache
2026-07-24 09:35:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (US/United States/ec2-52-34-72-225 ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (US/United States/ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-24 08:04:36
(3 days ago)
20 attempts against mh-misbehave-ban on pf102930
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-24 07:56:21
(3 days ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
IVski
2026-07-24 07:37:22
(3 days ago)
IVski WAF | Sensitive file probe detected - looking for .git
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
bancix
2026-07-24 07:30:40
(3 days ago)
2026/07/24 09:30:39 [error] 1044733#1044733: *112557 FastCGI sent in stderr: "Primary script unknown ...
show more
2026/07/24 09:30:39 [error] 1044733#1044733: *112557 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 52.34.72.225, server: site.cislveneto.it, request: "GET /info.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.2-fpm.sock:", host: "site.cislveneto.it"
2026/07/24 09:30:40 [error] 1044733#1044733: *112557 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 52.34.72.225, server: site.cislveneto.it, request: "GET /php.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.2-fpm.sock:", host: "site.cislveneto.it"
2026/07/24 09:30:40 [error] 1044733#1044733: *112557 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 52.34.72.225, server: site.cislveneto.it, request: "GET /i.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.2-fpm.sock:", host: "site.cislveneto.it"
...
show less
DDoS Attack
Email Spam
Port Scan
Spoofing
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-24 07:25:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:25:49.916844 2026] [security2:error] [pid 437764:tid 437764] [client 52.34.72.225:48698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "site.ablogisticsgroup.com"] [uri "/.git/config"] [unique_id "amMTfbc1EXgxohGN8OvIqQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 05:47:29
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:43:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.34.72.225 (ec2-52-34-72-225.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:43:15.996399 2026] [security2:error] [pid 3584047:tid 3584047] [client 52.34.72.225:54234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sislau.net"] [uri "/.git/config"] [unique_id "amL7c9NiqiVhahUfsntY7QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack