๐ฌ๐ง
PeravixGroup
2026-05-12 09:43:53
(1 month ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฌ๐ง
consul.to
2026-05-12 07:24:37
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
4server
2026-05-12 07:21:32
(1 month ago)
[TueMay1209:21:28.5090022026][security2:error][pid3870962:tid3871024][client104.207.38.1:0]ModSecuri ...
show more
[TueMay1209:21:28.5090022026][security2:error][pid3870962:tid3871024][client104.207.38.1:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.sito-online.ch\"][uri\"/.git/config\"][unique_id\"agLU-Kr5_rt_S8uI7URqKQAAAIA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
MAGIC
2026-05-03 02:40:29
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-04-30 13:50:02
(1 month ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-04-28 13:45:05
(1 month ago)
Try to access /.aws/credentials
Web App Attack
Anonymous
2026-04-18 15:58:45
(1 month ago)
Forum/form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-02-20 06:14:13
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 01:14:07.801849 2026] [security2:error] [pid 20492:tid 20492] [client 104.207.38.1:48775] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cobbwebb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cobbwebb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aZf7r_6gOifV-x7WzyXTFgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:57
(5 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2025-12-29 06:08:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 01:08:09.249100 2025] [security2:error] [pid 24353:tid 24353] [client 104.207.38.1:22719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artizandecor.com"] [uri "/.git/HEAD"] [unique_id "aVIayV0ItV0OVg2bhiQbGQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 05:30:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 00:30:22.918180 2025] [security2:error] [pid 31623:tid 31623] [client 104.207.38.1:58943] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmlogistics.com"] [uri "/.env"] [unique_id "aVIR7rDUwzFIegXAYl33RgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Little Iguana
2025-12-07 09:40:24
(6 months ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ฐ๐ท
Betatester
2025-11-29 07:06:00
(6 months ago)
Attempt to access /.svn/wc.db (source version control leak scan)
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-26 10:31:23
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.38.1 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 26 05:31:17.939672 2025] [security2:error] [pid 18317:tid 18317] [client 104.207.38.1:44477] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.siteworkestimating.com"] [uri "/.env"] [unique_id "aSbW9Sn9vZKMsaCZOBjuHAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2025-11-26 05:28:36
(6 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack