πΈπͺ
vaia.cloud
2026-07-25 06:10:02
(11 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π¬π§
consul.to
2026-07-25 01:49:39
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
π§π·
Halux
2026-07-25 01:03:55
(16 hours ago)
54.188.140.228 Probing protected path or service
Web App Attack
π³π±
homeshowdomain.nl
2026-07-24 22:02:20
(19 hours ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-07-24 14:59:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:59:17.382129 2026] [security2:error] [pid 474587:tid 474587] [client 54.188.140.228:47666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.firstclasstreatment.tijuanabible.org"] [uri "/.git/config"] [unique_id "amN9xfuPmsBMqjSZoZCqugAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-07-24 14:21:04
(1 day ago)
block ruleset likely probe for CVE-2025-55182 619E65C9C14E5E741C55CC8FD5E5630F031EBB6A
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 14:07:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:07:39.227956 2026] [security2:error] [pid 200475:tid 200475] [client 54.188.140.228:48314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.firingsquadfilms.com.interforce.com"] [uri "/.git/config"] [unique_id "amNxq5bjiAehx0Ncm2dbaQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
beon
2026-07-24 11:24:47
(1 day ago)
[DateTime=>2026-07-24T11:24:47Z to 2026-07-24T11:25:31Z (UTC)] , [HoneyPot_Hits=>259 times] , [Honey ...
show more
[DateTime=>2026-07-24T11:24:47Z to 2026-07-24T11:25:31Z (UTC)] , [HoneyPot_Hits=>259 times] , [HoneyPots=>/.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development and others] , [404targets=>/_environment, /phpinfo.php.bak, /phpinfo.php.old, /phpinfo.php~, /info.php.bak, /phpinfo.php.save and others] , [total_Hits=>270 times] , [hit_per_second=>6.13] , [Keyword=>WordPress, PHP web shells]
show less
Bad Web Bot
Web App Attack
Hacking
π«π·
largo-it.net
2026-07-24 09:40:30
(1 day ago)
Jul 24 11:40:08 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:52598 [24/Jul/2026:11:40:07.273] www_f ...
show more
Jul 24 11:40:08 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:52598 [24/Jul/2026:11:40:07.273] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/889/1218 404 200014 - - ---- 86/34/2/2/0 0/0 "POST /fr/ HTTP/1.1"
Jul 24 11:40:09 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:52598 [24/Jul/2026:11:40:08.969] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/850/892 404 200014 - - ---- 82/32/2/2/0 0/0 "POST /fr/ HTTP/1.1"
Jul 24 11:40:11 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:52598 [24/Jul/2026:11:40:10.320] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/917/958 404 200014 - - ---- 74/31/2/2/0 0/0 "POST /fr/ HTTP/1.1"
Jul 24 11:40:13 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:33964 [24/Jul/2026:11:40:12.222] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/883/1215 404 200005 - - ---- 81/32/3/3/0 0/0 "POST / HTTP/1.1"
Jul 24 11:40:26 vps-9f3cdc33 haproxy[2385295]: 54.188.140.228:39736 [24/Jul/2026:11:40:25.397] www_frontend~ finance_cluster/fina
...
show less
Hacking
Bad Web Bot
Web App Attack
π¨π
4server
2026-07-24 09:14:30
(1 day ago)
[FriJul2411:14:25.3342442026][security2:error][pid2742082:tid2742305][client54.188.140.228:0]ModSecu ...
show more
[FriJul2411:14:25.3342442026][security2:error][pid2742082:tid2742305][client54.188.140.228:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.fimka-icp.com.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"amMs8YMicDQ6co21SG-oTwAAAAE\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 08:37:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:37:19.609892 2026] [security2:error] [pid 29429:tid 29429] [client 54.188.140.228:34072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.filmpolis.vittariadesign.com"] [uri "/.git/config"] [unique_id "amMkPxAbowkDjxtaSV4QCAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-07-24 07:54:25
(1 day ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-24 07:38:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:37:59.986129 2026] [security2:error] [pid 3577094:tid 3577094] [client 54.188.140.228:47142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.file.kircali.net"] [uri "/.git/config"] [unique_id "amMWV_rc1AfdHsaeEXAPawAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 06:11:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:11:27.144308 2026] [security2:error] [pid 3599416:tid 3599416] [client 54.188.140.228:51918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fiestadj.spyasociados.com"] [uri "/.git/config"] [unique_id "amMCDzDWMlxXU3mXzjMp8wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 05:49:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.188.140.228 (ec2-54-188-140-228.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:49:50.250652 2026] [security2:error] [pid 501943:tid 502059] [client 54.188.140.228:41684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fiefseigneur.com.aafm.us"] [uri "/.git/config"] [unique_id "amL8_p2XQy1cURr41E1VBgAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack