๐บ๐ธ
IndigoRidge
2026-07-25 05:40:05
(5 hours ago)
54.255.182.203 - - [25/Jul/2026:01:39:40 -0400] "GET /.git/config HTTP/1.0" 404 38390 "-" "Mozilla/5 ...
show more
54.255.182.203 - - [25/Jul/2026:01:39:40 -0400] "GET /.git/config HTTP/1.0" 404 38390 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.255.182.203 - - [25/Jul/2026:01:39:41 -0400] "GET /.env HTTP/1.0" 404 38390 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
54.255.182.203 - - [25/Jul/2026:01:40:04 -0400] "GET /app/.env HTTP/1.0" 404 38390 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 02:40:37
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 22:40:32.764800 2026] [security2:error] [pid 20434:tid 20434] [client 54.255.182.203:51668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sbip.loneoakhoney.com"] [uri "/.git/config"] [unique_id "amQiIOnZThxx8Ht9VegE1gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:03:26
(13 hours ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 18:25:19
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:25:15.729548 2026] [security2:error] [pid 25289:tid 25289] [client 54.255.182.203:39988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.handyrehab.com"] [uri "/.git/config"] [unique_id "amOuC1FDUbB37CxwFeD9ZQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-07-24 18:16:29
(16 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:37:12
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:37:09.446752 2026] [security2:error] [pid 441608:tid 441608] [client 54.255.182.203:33828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.cms2020.com"] [uri "/.git/config"] [unique_id "amOixVkk6ZMBJ1octJL6ZgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:16:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:16:34.252833 2026] [security2:error] [pid 182550:tid 182550] [client 54.255.182.203:58580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.baystreet.news"] [uri "/.git/config"] [unique_id "amOd8v8R4ewv5AWbTdloIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-07-24 17:07:47
(18 hours ago)
Unauthorized connections HTTP 403
Web App Attack
๐ซ๐ท
Rom74
2026-07-24 16:10:29
(18 hours ago)
[Fri Jul 24 18:10:25.963560 2026] [security2:error] [pid 3821060:tid 130338550437568] [client 54.255 ...
show more
[Fri Jul 24 18:10:25.963560 2026] [security2:error] [pid 3821060:tid 130338550437568] [client 54.255.182.203:55738] [client 54.255.182.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.teslogiciels.com"] [uri "/"] [unique_id "amOOcbpm8tSvPQfP7XpNqgAAAE4"]
[Fri Jul 24 18:10:26.128075 2026] [security2:error] [pid 3821060:tid 130339154417344] [client 54.255.182.203:55738] [client 54.255.182.203] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 15:19:51
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:19:44.420350 2026] [security2:error] [pid 2660011:tid 2660011] [client 54.255.182.203:47720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terruven.badritual.art"] [uri "/.git/config"] [unique_id "amOCkP1Rc5kHLbuSs1QL0AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:57:40
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:57:35.243713 2026] [security2:error] [pid 15790:tid 15790] [client 54.255.182.203:58510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terms.oxfordgliding.com"] [uri "/.git/config"] [unique_id "amNvTyaz2FjHWrZhM5w7BQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-07-24 13:29:47
(21 hours ago)
Web scanning / probing for vulnerable paths | URL: /frontend/.env | Evidence: terminalb.pt 54.255.18 ...
show more
Web scanning / probing for vulnerable paths | URL: /frontend/.env | Evidence: terminalb.pt 54.255.182.203 - - [24/Jul/2026:15:28:18 +0200] \"GET /frontend/.env HTTP/1.1\" 404 22273 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: AMAZON-02 | Country: SG
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:28:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast ...
show more
(mod_security) mod_security (id:210492) triggered by 54.255.182.203 (ec2-54-255-182-203.ap-southeast-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:28:44.205332 2026] [security2:error] [pid 115027:tid 115027] [client 54.255.182.203:40790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.templeantiques.org"] [uri "/.git/config"] [unique_id "amMwTF3_4UYD37_zLUbARQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 08:15:07
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-24 06:32:15
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot