🇺🇸
TPI-Abuse
2026-09-07 00:16:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:16:13.121169 2026] [security2:error] [pid 7695:tid 7695] [client 54.252.181.147:51752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.shukrisharawico.com"] [uri "/.git/config"] [unique_id "ap4CTT5DN-tv8Rrt5AkZnQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-09-06 12:02:49
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-06 10:25:41
(1 day ago)
2026-09-06 06:25:41,205 fail2ban.actions [2535]: NOTICE [apache-auth] Ban 54.252.181.147
...
Port Scan
Brute-Force
🇮🇩
Burayot
2026-09-06 09:04:11
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.252.181.147 (AU/Australia/ec2-54- ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 54.252.181.147 (AU/Australia/ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 2 in the last 3600 secs
show less
Web App Attack
🇳🇱
sernate
2026-09-06 04:53:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (AU/Australia/ec2-54-252-181-147 ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (AU/Australia/ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 03:57:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:57:02.261435 2026] [security2:error] [pid 31510:tid 31510] [client 54.252.181.147:34532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.serenimedit.com"] [uri "/.git/config"] [unique_id "apzkjjYV1fgm3rL0GPyvJQAAAHA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 14:50:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 10:50:17.335357 2026] [security2:error] [pid 572:tid 572] [client 54.252.181.147:57952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.seasidesolutions.org"] [uri "/.git/config"] [unique_id "apwsKbIthAB96iVmgrJAdAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 04:20:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 00:20:18.653202 2026] [security2:error] [pid 12563:tid 12563] [client 54.252.181.147:44564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryan.robotrodeo.net"] [uri "/.git/config"] [unique_id "apuYgqdCs6aMo9A9zUhrjAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ph
2026-09-04 09:18:59
(3 days ago)
Bad web bot attempting to run wp-admin on non-WP site
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:55:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:54:55.122736 2026] [security2:error] [pid 405711:tid 405711] [client 54.252.181.147:39404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rwfrancis.com"] [uri "/.git/config"] [unique_id "apqHX4jpI006NUtr6jg_4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:18:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.252.181.147 (ec2-54-252-181-147.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:18:44.783577 2026] [security2:error] [pid 14255:tid 14255] [client 54.252.181.147:48952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rvtrips.robin5on.com"] [uri "/.git/config"] [unique_id "appUtIELA7Kgjq7PyfZipgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-04 04:54:05
(4 days ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-03 22:02:24
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-03
Web App Attack
SSH
Hacking
🇵🇱
strefapi_com
2026-09-03 13:49:08
(4 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-03 12:30:58
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking