๐บ๐ธ
TPI-Abuse
2026-08-27 22:58:35
(2 minutes ago)
(mod_security) mod_security (id:210730) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast ...
show more
(mod_security) mod_security (id:210730) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:58:31.424489 2026] [security2:error] [pid 6483:tid 6483] [client 54.169.226.122:49466] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nnrentacar.com|F|2"] [data ".nnrentacar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nnrentacar.com"] [uri "/z9x8c7v6b5-debug-trigger-www.nnrentacar.com"] [unique_id "apDBFz0obS7PDwEpQxQ7EAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-27 22:55:48
(4 minutes ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 54.169.226.122 (SG/Singapore/ec2-54-169- ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 54.169.226.122 (SG/Singapore/ec2-54-169-226-122.ap-southeast-1.compute.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 54.169.226.122 - - [28/Aug/2026:00:55:45 +0200] "GET /secrets.env HTTP/2.0" 200 11828 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" "100.117.78.57" host=falone.com
show less
Port Scan
๐บ๐ธ
factor1
2026-08-27 22:51:45
(8 minutes ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐ฉ๐ช
bazter.pro
2026-08-27 22:21:17
(39 minutes ago)
Auto-Ban [2026-08-27 22:21:17]: CRITICAL: bot trap (soft) | host=geoproceso.com | route=/api/trap/ca ...
show more
Auto-Ban [2026-08-27 22:21:17]: CRITICAL: bot trap (soft) | host=geoproceso.com | route=/api/trap/catalog-export | hits=1 | ua=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:55:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:55:33.146451 2026] [security2:error] [pid 32324:tid 32324] [client 54.169.226.122:55464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vitalitywebb.com"] [uri "/@fs/var/task/.env"] [unique_id "apCkRZXSMzDA4ynG6YmRvQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 20:26:03
(2 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git-credentials (+3 more) | 2026-08-27 20:26 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-27 20:11:03
(2 hours ago)
54.169.226.122 arduino.ua [27/Aug/2026:23:11:03 +0300] "GET /.git/config HTTP/2.0" 403 146 "-" "Mozi ...
show more
54.169.226.122 arduino.ua [27/Aug/2026:23:11:03 +0300] "GET /.git/config HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] " 0.000 2387
...
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
macrob
2026-08-27 19:33:43
(3 hours ago)
2026/08/27 19:33:23 [error] 2898861#2898861: *527560354 access forbidden by rule, client: 54.169.226 ...
show more
2026/08/27 19:33:23 [error] 2898861#2898861: *527560354 access forbidden by rule, client: 54.169.226.122, server: finami.mx, request: "GET /.vite/manifest.json HTTP/2.0", host: "finami.mx"
2026/08/27 19:33:23 [error] 2898857#2898857: *527576958 access forbidden by rule, client: 54.169.226.122, server: finami.mx, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "finami.mx"
2026/08/27 19:33:38 [error] 2898857#2898857: *527577006 access forbidden by rule, client: 54.169.226.122, server: finami.mx, request: "GET /admin/login HTTP/2.0", host: "finami.mx"
...
show less
Web App Attack
Anonymous
2026-08-27 19:20:16
(3 hours ago)
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log ...
show more
[osotir.org] httpd-config-scan: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=/@fs/../.env?raw?? | /@fs/app/.env?raw?? | /@fs/src/.env?raw??
show less
Hacking
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-27 16:49:00
(6 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-27 16:09:13
(6 hours ago)
Bot / seems abusive / Apache connections: 22
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-27 14:45:35
(8 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.169.226.122 (SG/Singapore/ec2-54- ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.169.226.122 (SG/Singapore/ec2-54-169-226-122.ap-southeast-1.compute.amazonaws.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:40:57
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.226.122 (ec2-54-169-226-122.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:40:49.686663 2026] [security2:error] [pid 22463:tid 22463] [client 54.169.226.122:55154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mavikalem.org"] [uri "/.git/config"] [unique_id "apBMcdb_2zgbACe_h0nCRwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-27 13:42:10
(9 hours ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ต๐ฑ
TaKeN
2026-08-27 10:19:06
(12 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-08-27T12:19:06+02:00 and 2026-08-27T12:19:06+02:00. Sample requested paths: /.hermes/config.yaml.
show less
Web App Attack
Hacking