๐บ๐ธ
TPI-Abuse
2026-07-28 06:41:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 02:41:37.073509 2026] [security2:error] [pid 1425033:tid 1425033] [client 54.169.84.173:50732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aspotoftea.com"] [uri "/.git/config"] [unique_id "amhPIQ1uVph10LLwSuHXWwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:21:39
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:21:32.370195 2026] [security2:error] [pid 811195:tid 811195] [client 54.169.84.173:56868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.es"] [uri "/.git/config"] [unique_id "amd3fOgmXG1QAPfV_cfmsAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-27 11:58:22
(22 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5. ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
๐ณ๐ฑ
e.fierstra
2026-07-26 23:02:35
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 17:14:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 13:14:46.390890 2026] [security2:error] [pid 1944756:tid 1944756] [client 54.169.84.173:39738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.formationone.com"] [uri "/.git/config"] [unique_id "amTvBq4R6stkItfQVAbIIwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:56:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:56:45.880182 2026] [security2:error] [pid 443534:tid 443534] [client 54.169.84.173:38926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scc1.us"] [uri "/.git/config"] [unique_id "amOLPS580hB6uFYhsGjIXAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:16:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.169.84.173 (ec2-54-169-84-173.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:16:49.626387 2026] [security2:error] [pid 30894:tid 30894] [client 54.169.84.173:32888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.robtown.com"] [uri "/.git/config"] [unique_id "amNJob4gkt8sNcj70smfsgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 09:24:29
(4 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 09:05:06
(4 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
Anonymous
2026-07-24 08:48:22
(4 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack