Anonymous
2026-07-26 08:06:03
(6 hours ago)
Blocked: Reason='High 404 error volume (> 1000 in 60 min)'; Requests=1349
Hacking
๐ฉ๐ช
big-cloud.nl
2026-07-26 05:53:51
(8 hours ago)
Try to access /.git/config
Web App Attack
๐ฎ๐ฉ
rafli
2026-07-26 05:02:00
(9 hours ago)
{"level":"info","ts":1785042112.163455,"logger":"http.log.access.log18","msg":"handled request","req ...
show more
{"level":"info","ts":1785042112.163455,"logger":"http.log.access.log18","msg":"handled request","request":{"remote_ip":"52.41.45.160","remote_port":"42474","client_ip":"52.41.45.160","proto":"HTTP/1.1","method":"POST","host":"klikcair.oncall.id","uri":"/dashboard","headers":{"Accept-Encoding":["gzip, deflate"],"Accept":["*/*"],"Connection":["keep-alive"],"X-Nextjs-Request-Id":["9ac0fa24"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Next-Action":["x"],"Content-Type":["multipart/form-data; boundary=--------WebKitFormBoundaryce8e189294f847b1"],"Content-Length":["748"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"klikcair.oncall.id","ech":false}},"bytes_read":748,"user_id":"","duration":0.010467598,"size":24,"status":404,"resp_headers":{"Vary":["rsc, next-router-state-tree, next-router-prefetch, next-router-segment-prefetch, Accept-Encoding"],"Cache-Control":
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 04:22:00
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 00:21:55.672191 2026] [security2:error] [pid 3740482:tid 3740482] [client 52.41.45.160:45046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "klfreeman.com"] [uri "/.git/config"] [unique_id "amWLY5N9mactHX8xxMozLAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-26 03:04:12
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:03:08
(16 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-07-25 05:01:33
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 03:15:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:15:28.871779 2026] [security2:error] [pid 30131:tid 30131] [client 52.41.45.160:34790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeremymetzger.com"] [uri "/.git/config"] [unique_id "amQqUL2BfBK92ypwUiEOFgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
alecj.com
2026-07-25 02:28:56
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ซ๐ท
Octopuce
2026-07-25 02:09:05
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
Anonymous
2026-07-25 01:51:31
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-24 12:05:35
(2 days ago)
Scanning/Probing (31)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:19:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.41.45.160 (ec2-52-41-45-160.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:19:27.590808 2026] [security2:error] [pid 4028467:tid 4028467] [client 52.41.45.160:41524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hi-niemczuras.net"] [uri "/.git/config"] [unique_id "amNKP4wGJ_F-SPR8MaYPvQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
aks4226
2026-07-24 11:02:22
(2 days ago)
Bot search, attacking common web applications.
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-24 10:18:02
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 52.41.45.160 (US/United States/Oregon/B ...
show more
(mod_security) mod_security triggered on hostname [redacted] 52.41.45.160 (US/United States/Oregon/Boardman/ec2-52-41-45-160.us-west-2.compute.amazonaws.com)
show less
SQL Injection