Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=437; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.en ...
show more
Apache probe; attempts=437; exact paths: /.env | /.env.backup | /.env.backup1 | /.env.backup2 | /.env.backup/ | /.env.bak | /.env.bak/ | /.env.ci | /.env.dev | /.env.dev/ | /.env.development | /.env.development/ | /.env.dist | /.env.docker | /.env.example | /.env.example/ | /.env.fly | /.env.json | /.env.live | /.env.local | /.env.local/ | /.env.neon | /.env.old | /.env.old/ | /.env.preprod | /.env.prod | /.env.production | /.env.production/ | /.env.railway | /.env.remote | /.env.remote/ | /.env.render | /.env.sample | /.env.sample/ | /.env.save | /.env.save/ | /.env.stage | /.env.staging | /.env.staging/ | /.env.supabase | /.env.swp | /.env.test | /.env.test/ | /.env.txt | /.env.uat | /.env.vault | /.env.vercel | /.env.yaml | /.env.yml | /.env/ | /.env~ | /.git/.env | /.git/config | /.git/config/ | /actions/.env | /admin-panel/.env | /admin/.env | /administrator/.env | /angular/.env | /ansible/.env | /api/. | ... [226 exact paths total]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 05:08:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:08:01.558850 2026] [security2:error] [pid 2888008:tid 2888008] [client 54.179.177.209:49356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "db.nyemdr.org"] [uri "/.git/config"] [unique_id "amg5MQLW6MXdXVFCvJ_rDgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 04:06:05
(3 days ago)
Blocked: Reason='High 404 error volume (> 1000 in 60 min)'; Requests=1583
Hacking
๐ฉ๐ช
Hary74656
2026-07-28 04:02:56
(3 days ago)
[Tue Jul 28 06:02:47.052522 2026] [security2:error] [pid 251769:tid 251951] [client 54.179.177.209:5 ...
show more
[Tue Jul 28 06:02:47.052522 2026] [security2:error] [pid 251769:tid 251951] [client 54.179.177.209:50252] [client 54.179.177.209] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})|[<>]\\\\(.*\\\\))" at ARGS:0. [file "/usr/share/modsecurity-crs/rules/REQUEST-932-APPLICATION-ATTACK-RCE.conf"] [line "367"] [id "932130"] [msg "Remote Command Execution: Unix Shell Expression Found"] [data "Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-shell"] [tag "platform-unix"] [tag "a
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-28 03:41:42
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-07-27 22:00:29
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-27
Web App Attack
SSH
Hacking
๐ซ๐ท
dynamix
2026-07-27 10:28:19
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-26 23:33:03
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
R.G.
2026-07-24 23:41:35
(6 days ago)
(ScanningForFiles) Scanning for files triggerd 54.179.177.209 (SG/Singapore/ec2-54-179-177-209.ap-so ...
show more
(ScanningForFiles) Scanning for files triggerd 54.179.177.209 (SG/Singapore/ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com): 10 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-07-24 20:59:46
(6 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-24 09:01:18
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-07-24 06:36:51
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 54.179.177.209 (SG/Singapore/ec2-54-179 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 54.179.177.209 (SG/Singapore/ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-07-24 06:16:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:16:04.527749 2026] [security2:error] [pid 501938:tid 501970] [client 54.179.177.209:60954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingeconsultcr.com"] [uri "/.git/config"] [unique_id "amMDJLiUl2r1sCV9ZPb9lQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:55:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:55:21.046030 2026] [security2:error] [pid 3915167:tid 3915167] [client 54.179.177.209:56286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ingberinteriors.com"] [uri "/.git/config"] [unique_id "amL-SSc9-rQPJC1vIRStzQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:44:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.179.177.209 (ec2-54-179-177-209.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:44:07.311163 2026] [security2:error] [pid 3147718:tid 3147718] [client 54.179.177.209:49570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infraredovens.net"] [uri "/.git/config"] [unique_id "amLfh3W6G6wIIpjMQ7XiAgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack