๐บ๐ธ
kosada.com
2026-07-27 18:54:02
(47 minutes ago)
Web vulnerability probing: /api/dev/.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:53:53
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:53:45.418760 2026] [security2:error] [pid 1210163:tid 1210163] [client 54.202.241.183:50072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.researchdesk.jmnr.net"] [uri "/.git/config"] [unique_id "amepOR08HIwEn_APPK3IlQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 18:18:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:18:20.619523 2026] [security2:error] [pid 785913:tid 785913] [client 54.202.241.183:37976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rescuedpekes.com.aarce.me"] [uri "/.git/config"] [unique_id "ameg7IWF4H1lU6haS_QHCAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:31:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:31:27.504696 2026] [security2:error] [pid 1736894:tid 1736894] [client 54.202.241.183:50014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.representacionesthompson.com.nesetsv.com"] [uri "/.git/config"] [unique_id "amd5z0llEXBxNLPEphXbbQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 12:18:10
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 11:46:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:45:55.563691 2026] [security2:error] [pid 661113:tid 661113] [client 54.202.241.183:42156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.repair.cloudex.link"] [uri "/.git/config"] [unique_id "amdE8zfHmngQ0IGMfa-KkgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 11:42:22
(7 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:21:14
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:21:07.841603 2026] [security2:error] [pid 411845:tid 411845] [client 54.202.241.183:39454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rentbright.hangrypandas.com"] [uri "/.git/config"] [unique_id "amcjA0GQ1cBR73OEZsyyRAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 05:06:37
(14 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (41/60 min)'; Requests=41
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-27 04:49:41
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:49:34.645479 2026] [security2:error] [pid 3351753:tid 3351753] [client 54.202.241.183:42586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.renjunews.renju.net"] [uri "/.git/config"] [unique_id "ambjXv0RcQp5DMAdSikBBQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-26 10:30:05
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 09:15:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.202.241.183 (ec2-54-202-241-183.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 05:15:30.106347 2026] [security2:error] [pid 16790:tid 16790] [client 54.202.241.183:37796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rheemhvac.savingshvac.com"] [uri "/.git/config"] [unique_id "amXQMlambEd3AC43Znc4hQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-26 06:04:27
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ฑ๐ป
garmtech.com
2026-07-26 04:44:33
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.env
Web App Attack
๐ฟ๐ฆ
conure
2026-07-26 04:19:13
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack