๐จ๐ญ
TheCoon
2026-07-27 15:00:01
(9 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-27 09:11:46
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:11:40.397042 2026] [security2:error] [pid 3641953:tid 3641953] [client 54.217.42.135:46194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schwanpaint.com"] [uri "/.git/config"] [unique_id "amcgzCxHBMwnGifHhbBm0QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-27 06:11:40
(18 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฉ๐ช
raph
2026-07-27 05:51:15
(18 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-27 05:14:11
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 54.217.42.135 (IE/Ireland/Leinster/Dubl ...
show more
(mod_security) mod_security triggered on hostname [redacted] 54.217.42.135 (IE/Ireland/Leinster/Dublin/ec2-54-217-42-135.eu-west-1.compute.amazonaws.com)
show less
SQL Injection
๐ฉ๐ช
MarkGGN
2026-07-27 05:01:08
(19 hours ago)
Web attack. 54.217.42.135 - - [27/Jul/2026:07:01:07 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" " ...
show more
Web attack. 54.217.42.135 - - [27/Jul/2026:07:01:07 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.217.42.135 - - [27/Jul/2026:07:01:08 +0200] "GET /.env HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 04:30:50
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 00:30:44.880539 2026] [security2:error] [pid 2932783:tid 2932795] [client 54.217.42.135:43210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schoprint.com"] [uri "/.git/config"] [unique_id "ambe9IkuK1dAF2a_C6SpDQAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-07-26 08:50:34
(1 day ago)
54.217.42.135 - - [26/Jul/2026:09:50:32 +0100] "GET /.git/config HTTP/1.1" 404 158 "-" "Mozilla/5.0 ...
show more
54.217.42.135 - - [26/Jul/2026:09:50:32 +0100] "GET /.git/config HTTP/1.1" 404 158 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
Web App Attack
๐บ๐ธ
stvnrdg.me
2026-07-26 08:13:44
(1 day ago)
54.217.42.135 - - [26/Jul/2026:08:13:44 +0000] "GET /phpinfo.php HTTP/1.1" 404 451 "-" "Mozilla/5.0 ...
show more
54.217.42.135 - - [26/Jul/2026:08:13:44 +0000] "GET /phpinfo.php HTTP/1.1" 404 451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-25 04:24:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:23:57.600044 2026] [security2:error] [pid 2419929:tid 2420069] [client 54.217.42.135:60684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saryatech.pershia.net"] [uri "/.git/config"] [unique_id "amQ6XS_76_NuB1vTmeGeAgAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 01:01:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 54.217.42.135 (ec2-54-217-42-135.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 21:01:50.988452 2026] [security2:error] [pid 3611880:tid 3611880] [client 54.217.42.135:41074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahwhitecotton.com"] [uri "/.git/config"] [unique_id "amQK_sgKOuyClIzyjudZnQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 00:08:44
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-25 00:05:42
(3 days ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-24 23:40:02
(3 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:03:13
(3 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking