πΊπΈ
TPI-Abuse
2026-09-24 00:28:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:28:03.803287 2026] [security2:error] [pid 308:tid 308] [client 54.243.25.221:8069] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earlyfordv8crrg10.com"] [uri "/api/.env"] [unique_id "arRuk1vL1PsNYr8LfSbytgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 20:21:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:21:09.201640 2026] [security2:error] [pid 18356:tid 18356] [client 54.243.25.221:5027] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bacpool.com"] [uri "/backend/.env"] [unique_id "arLjNRox9_DyiSUDC2TRfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 19:00:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:00:36.445782 2026] [security2:error] [pid 21754:tid 21754] [client 54.243.25.221:44719] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.assec.org|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.assec.org"] [uri "/config.php.bak"] [unique_id "arLQVFLAuO2FVfPC1D0nHgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
SentinalX by uzumaru
2026-09-19 03:43:30
(5 days ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: api.ipify.org:443
show less
Open Proxy
Port Scan
πΊπΈ
TPI-Abuse
2026-09-18 13:26:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 09:26:10.719517 2026] [security2:error] [pid 21837:tid 21837] [client 54.243.25.221:42637] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rochesterhistorical.org"] [uri "/wp-config.php.bak.php"] [unique_id "aq078kdH02o1lfyZZT70GQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 03:05:05
(6 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 12:51:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:51:18.696245 2026] [security2:error] [pid 9392:tid 9392] [client 54.243.25.221:24750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.artaria.us"] [uri "/api/.env"] [unique_id "aqviRgILkbmchS6lgjtMUAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 04:24:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:24:18.689427 2026] [security2:error] [pid 29343:tid 29343] [client 54.243.25.221:19717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koshland.org"] [uri "/wp-config.php.old"] [unique_id "aqtrcqE8Ts4H3n1Qk55uVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 13:57:25
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.243.25.221 (ec2-54-243-25-221.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:57:21.065009 2026] [security2:error] [pid 19600:tid 19643] [client 54.243.25.221:42820] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cityofmiddleton.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cityofmiddleton.org"] [uri "/error.log"] [unique_id "aqqgQdaJFskwiv5ealdU6QAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack