πΊπΈ
TPI-Abuse
2026-07-26 02:42:34
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 22:42:27.550970 2026] [security2:error] [pid 3310005:tid 3310005] [client 54.200.128.15:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr.com"] [uri "/.git/config"] [unique_id "amV0E4WjdX6ovSH0idpFwAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-07-25 22:01:26
(4 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-25 00:55:38
(1 day ago)
54.200.128.15 - - [25/Jul/2026:02:55:27 +0200] "GET /.git/config HTTP/1.1" 403 625 "-" "Mozilla/5.0 ...
show more
54.200.128.15 - - [25/Jul/2026:02:55:27 +0200] "GET /.git/config HTTP/1.1" 403 625 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.200.128.15 - - [25/Jul/2026:02:55:27 +0200] "GET /.env HTTP/1.1" 403 625 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.200.128.15 - - [25/Jul/2026:02:55:28 +0200] "GET /.env.local HTTP/1.1" 403 625 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.200.128.15 - - [25/Jul/2026:02:55:28 +0200] "GET /.env.production HTTP/1.1" 403 625 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.200.128.15 - - [25/Jul/2026:02:55:28 +0200] "GET /.env.staging HTTP/1.1" 403 625 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
DDoS Attack
πΊπΈ
TPI-Abuse
2026-07-25 00:17:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:17:05.666639 2026] [security2:error] [pid 1155401:tid 1155401] [client 54.200.128.15:51590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "neconebooks.com"] [uri "/.git/config"] [unique_id "amQAgVzW4cH9QS6wRATXOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure
2026-07-24 11:29:38
(1 day ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 11:28:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:27:59.280377 2026] [security2:error] [pid 2278374:tid 2278374] [client 54.200.128.15:56196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sharawi-gum.com"] [uri "/.git/config"] [unique_id "amNMP2bykLCebKx09qnclgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 10:45:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:45:28.232750 2026] [security2:error] [pid 3757011:tid 3757011] [client 54.200.128.15:53150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shannonmahoney.com"] [uri "/.git/config"] [unique_id "amNCSM7xNO14FqMJdM2u4AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Dave Hansen
2026-07-24 10:02:52
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 54.200.128.15 (US/United States/ec2-54- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 54.200.128.15 (US/United States/ec2-54-200-128-15.us-west-2.compute.amazonaws.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-07-24 10:00:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:00:42.455151 2026] [security2:error] [pid 269019:tid 269027] [client 54.200.128.15:56910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shaneblair.com"] [uri "/.git/config"] [unique_id "amM3ystXSS-PTNrv_4fNSgAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 07:24:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:24:29.762437 2026] [security2:error] [pid 6415:tid 6415] [client 54.200.128.15:60124] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shadowfree.souldata.com"] [uri "/.git/config"] [unique_id "amMTLeTP79--0W7HyH25qAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 06:17:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:17:33.429373 2026] [security2:error] [pid 2891243:tid 2891247] [client 54.200.128.15:42090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sh2.lol"] [uri "/.git/config"] [unique_id "amMDfTRnfK5YQ-ibrEdaSgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πΎ
shopmax
2026-07-24 06:09:49
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-07-24 05:39:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.200.128.15 (ec2-54-200-128-15.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:39:30.973016 2026] [security2:error] [pid 107392:tid 107392] [client 54.200.128.15:60628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sguard.co"] [uri "/.git/config"] [unique_id "amL6kh30Pi4ImMUrzQprvAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-07-24 04:23:09
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack