๐ฎ๐น
clamehost.it
2026-07-26 03:54:23
(2 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
Anonymous
2026-07-26 01:31:02
(4 hours ago)
(caddyscan) Scanner path probe from 52.53.201.36 (US/United States/ec2-52-53-201-36.us-west-1.comput ...
show more
(caddyscan) Scanner path probe from 52.53.201.36 (US/United States/ec2-52-53-201-36.us-west-1.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 52.53.201.36 - - [26/Jul/2026:01:30:59 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 52.53.201.36 - - [26/Jul/2026:01:30:59 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 52.53.201.36 - - [26/Jul/2026:01:30:59 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 52.53.201.36 - - [26/Jul/2026:01:30:59 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 52.53.201.36 - - [26/Jul/2026:01:30:59 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-25 14:02:16
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 10:02:13.123847 2026] [security2:error] [pid 8151:tid 8151] [client 52.53.201.36:60810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yun-san.com"] [uri "/.git/config"] [unique_id "amTB5Y97gM8NegZZ-yukSAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 10:45:41
(19 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:32:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:32:33.151328 2026] [security2:error] [pid 1080775:tid 1080775] [client 52.53.201.36:47544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drbolen.com"] [uri "/.git/config"] [unique_id "amOhseqrI8Gsn8p0tVmF5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 14:14:27
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-24 11:01:46
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 52.53.201.36 (US/United States/Californ ...
show more
(mod_security) mod_security triggered on hostname [redacted] 52.53.201.36 (US/United States/California/San Jose/ec2-52-53-201-36.us-west-1.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-24 10:12:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:12:36.018580 2026] [security2:error] [pid 3403837:tid 3403837] [client 52.53.201.36:54310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.delidalga.com"] [uri "/.git/config"] [unique_id "amM6lP6Ep48uyAvzs5XOLgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 08:21:01
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:19:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 52.53.201.36 (ec2-52-53-201-36.us-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:19:22.660125 2026] [security2:error] [pid 1994480:tid 1994480] [client 52.53.201.36:55622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "amMgCls1mWmXz90LgWVBVwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-07-24 07:54:32
(1 day ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 06:15:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2024-11-08 02:25:15
(1 year ago)
anomaly: udp_src_session, 5001 > threshold 5000, repeats 717 times since last log
Port Scan