๐ฆ๐บ
CalmBrain
2026-07-18 16:00:36
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐ณ
evicky2002
2026-07-18 06:00:00
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฒ๐ฝ
octageeks.com
2026-07-18 04:13:17
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-17 22:04:03
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-16.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-17 13:13:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 09:13:18.686005 2026] [security2:error] [pid 25898:tid 25898] [client 54.203.130.134:34350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tci.land"] [uri "/.env.old"] [unique_id "aloqbhAl1zeGUZIl_913JAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:57:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:57:11.671152 2026] [security2:error] [pid 779385:tid 779385] [client 54.203.130.134:15442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compliancedepts.com"] [uri "/.env.example"] [unique_id "aloYl5D4LTrpUGV3C44oGwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:38:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:38:29.551353 2026] [security2:error] [pid 19977:tid 19977] [client 54.203.130.134:39586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lanegraves.com"] [uri "/.env.development"] [unique_id "aloUNbZ-h19ll6_4L6TiOQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:43:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:43:51.510628 2026] [security2:error] [pid 9519:tid 9519] [client 54.203.130.134:4596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colorwize.com"] [uri "/.env.prod"] [unique_id "aloHZ11Y6yVO8p7UUhPbdwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
blik2108
2026-07-17 10:26:47
(2 days ago)
beta.sleepylizard.com:443 54.203.130.134 - - [17/Jul/2026:11:26:45 +0100] "GET /config.yaml HTTP/1.1 ...
show more
beta.sleepylizard.com:443 54.203.130.134 - - [17/Jul/2026:11:26:45 +0100] "GET /config.yaml HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 54.203.130.134 - - [17/Jul/2026:11:26:46 +0100] "GET /config.yml HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 54.203.130.134 - - [17/Jul/2026:11:26:46 +0100] "GET /config.toml HTTP/1.1" 200 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36 (Silvy X Ran; +https://silvyxran.love; +https://silver.inc)"
beta.sleepylizard.com:443 54.203.130.134 - - [17/Jul/2026:11:26:47 +0100] "GET /config/production.json HTTP/1.1" 200 819 "-" "Mozilla/5.0
...
show less
Brute-Force
๐ซ๐ท
largo-it.net
2026-07-17 10:23:04
(2 days ago)
Jul 17 12:22:45 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:49196 [17/Jul/2026:12:22:45.539] www_f ...
show more
Jul 17 12:22:45 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:49196 [17/Jul/2026:12:22:45.539] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/384/395 404 3252 - - ---- 65/18/0/0/0 0/0 "GET /.env~ HTTP/1.1"
Jul 17 12:23:01 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:11142 [17/Jul/2026:12:23:00.869] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/324/335 404 3252 - - ---- 67/20/0/0/0 0/0 "GET /.envrc HTTP/1.1"
Jul 17 12:23:01 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:11142 [17/Jul/2026:12:23:01.425] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/316/327 404 3252 - - ---- 68/20/0/0/0 0/0 "GET /.flaskenv HTTP/1.1"
Jul 17 12:23:02 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:11142 [17/Jul/2026:12:23:01.983] www_frontend~ finance_cluster/finance1_test1_https 0/0/11/328/339 404 3252 - - ---- 67/20/0/0/0 0/0 "GET /env HTTP/1.1"
Jul 17 12:23:02 vps-9f3cdc33 haproxy[1195832]: 54.203.130.134:11142 [17/Jul/2026:12:23:02.566] www_frontend~ finance_cluster/fina
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 10:02:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 06:02:52.222407 2026] [security2:error] [pid 17001:tid 17001] [client 54.203.130.134:7772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mail-rfinder.com.suffolksystems.com"] [uri "/.env.test"] [unique_id "aln9zKZA2p1XR6RiWOIHwQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Halux
2026-07-17 09:54:02
(2 days ago)
54.203.130.134 Probing protected path or service
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-17 08:44:06
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 08:23:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:23:08.175492 2026] [security2:error] [pid 21298:tid 21298] [client 54.203.130.134:9212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.okapi.ic1.biz"] [uri "/.env"] [unique_id "alnmbN-u3nCb2GJRsIrSlAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 07:56:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.co ...
show more
(mod_security) mod_security (id:210492) triggered by 54.203.130.134 (ec2-54-203-130-134.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:56:32.829066 2026] [security2:error] [pid 449879:tid 449879] [client 54.203.130.134:28688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.limegreengirl.michaelward.com"] [uri "/.env"] [unique_id "alngMBQjync69lN3Ts0ufQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack