๐ง๐ฌ
Filipe Dรกvila
2025-11-16 12:21:52
(10 months ago)
[Sun Nov 16 07:21:51.184215 2025] [:error] [pid 439475:tid 140666445211392] [client 52.59.133.130:58 ...
show more
[Sun Nov 16 07:21:51.184215 2025] [:error] [pid 439475:tid 140666445211392] [client 52.59.133.130:58288] [client 52.59.133.130] [redacted]: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "[redacted][redacted]"] [[redacted] "233"] [id "[redacted]"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "[redacted]/4.7.0-dev"] [tag "[redacted]"] [tag "[redacted]"] [hostname "training.[redacted]"] [uri "/.env"] [unique_id "aRnB370R0DkZg2OOiscz6AAAAEw"]
show less
Web App Attack
๐จ๐ญ
zynex
2025-11-16 11:59:51
(10 months ago)
URL Probing: /application/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 07:43:17
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 02:43:12.644615 2025] [security2:error] [pid 28638:tid 28638] [client 52.59.133.130:35384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "truthsabouthealthcare.com"] [uri "/.env.prod"] [unique_id "aRmAkNifCfocKNHn_NY0vwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-16 05:39:24
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 16 00:39:17.714866 2025] [security2:error] [pid 7504:tid 7583] [client 52.59.133.130:44818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triestemagica.org"] [uri "/.env.local"] [unique_id "aRljhVkujaBiMNECjmGtqAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-11-16 04:22:26
(10 months ago)
LF_APACHE_403: 52.59.133.130 (DE/Germany/ec2-52-59-133-130.eu-central-1.compute.amazonaws.com), more ...
show more
LF_APACHE_403: 52.59.133.130 (DE/Germany/ec2-52-59-133-130.eu-central-1.compute.amazonaws.com), more than 10 Apache 403 hits in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2025-11-15 23:05:48
(10 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-11-14.
show less
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2025-11-15 14:43:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 15 09:43:41.348833 2025] [security2:error] [pid 4365:tid 4365] [client 52.59.133.130:60558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepfer.org"] [uri "/.env"] [unique_id "aRiRnfr-8v5k0Pucwt7hYgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-15 03:46:55
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 22:46:51.772738 2025] [security2:error] [pid 17944:tid 17944] [client 52.59.133.130:50700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heihu.org.cn.englishmagic.us"] [uri "/.git/config"] [unique_id "aRf3q6sJoM7W1hrMujvtCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-11-14 19:35:07
(10 months ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-14 16:29:33
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.c ...
show more
(mod_security) mod_security (id:210492) triggered by 52.59.133.130 (ec2-52-59-133-130.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 14 11:29:28.421331 2025] [security2:error] [pid 5691:tid 5691] [client 52.59.133.130:53312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.davidleecrites.com.whatifandwhynot.xyz"] [uri "/.git/config"] [unique_id "aRdY6GT86zucuq3tKJ1mbwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack