๐ซ๐ท
Lunix
2026-08-01 10:06:53
(6 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 09:45:53
(6 hours ago)
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 05:45:46.711676 2026] [security2:error] [pid 342345:tid 342359] [client 104.252.175.42:42682] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.127:443|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.127"] [uri "/hello.world"] [unique_id "am3ASmWLFKRBLhsrL4h9cAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
djboddington
2026-08-01 09:12:13
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/ssh-slow-bf
SSH
Brute-Force
๐ท๐บ
kipfelโ
2026-08-01 06:10:37
(10 hours ago)
2026-08-01T13:05:08.236547+07:00 justhost-vm-arcturus-1c2g-ovb sshd-session[2059080]: Invalid user a ...
show more
2026-08-01T13:05:08.236547+07:00 justhost-vm-arcturus-1c2g-ovb sshd-session[2059080]: Invalid user admin from 104.252.175.42 port 47614
2026-08-01T13:05:50.077975+07:00 justhost-vm-arcturus-1c2g-ovb sshd-session[2059085]: Invalid user orangepi from 104.252.175.42 port 59366
2026-08-01T13:10:36.381752+07:00 justhost-vm-arcturus-1c2g-ovb sshd-session[2059147]: Invalid user test from 104.252.175.42 port 42342
...
show less
Brute-Force
SSH
๐ฎ๐ณ
evicky2002
2026-08-01 06:00:00
(10 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-08-01 05:09:36
(11 hours ago)
Apache HTTP Server Directory Traversal.
Web App Attack
Anonymous
2026-08-01 03:41:22
(12 hours ago)
104.252.175.42 - - [01/Aug/2026:00:41:21 -0300] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.% ...
show more
104.252.175.42 - - [01/Aug/2026:00:41:21 -0300] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" Dest:Port 80 HTTP_Status: 400
...
show less
Web App Attack
๐ฉ๐ช
Panter
2026-08-01 02:14:25
(14 hours ago)
Bruteforce detected by fail2ban SSH
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-01 02:07:36
(14 hours ago)
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 22:07:33.127907 2026] [security2:error] [pid 3325381:tid 3325381] [client 104.252.175.42:44838] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.16:443|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.16"] [uri "/hello.world"] [unique_id "am1U5cY19pi7Y0acq2If1QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Vaction
2026-08-01 00:31:41
(15 hours ago)
104.252.175.42 - - [01/Aug/2026:02:31:41 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.% ...
show more
104.252.175.42 - - [01/Aug/2026:02:31:41 +0200] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 432 "-" "libredtail-http"
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-01 00:20:20
(16 hours ago)
Unauthorized connection attempt detected, SSH Brute-Force
Brute-Force
Port Scan
SSH
๐ซ๐ท
LRNP
2026-08-01 00:02:55
(16 hours ago)
_:443 104.252.175.42 - - [01/Aug/2026:00:02:55 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval ...
show more
_:443 104.252.175.42 - - [01/Aug/2026:00:02:55 +0000] "GET /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/1.1" 404 146 "-" "libredtail-http"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 23:46:03
(16 hours ago)
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:218420) triggered by 104.252.175.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 19:45:59.189879 2026] [security2:error] [pid 7589:tid 7589] [client 104.252.175.42:49798] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "22"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||192.64.150.105:80|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "192.64.150.105"] [uri "/hello.world"] [unique_id "am0zt_4NZuz3XFqAIBVXYQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mainpine
2026-07-31 23:35:06
(16 hours ago)
probing for vulnerable web apps
Web App Attack
๐ฉ๐ช
Vincent Falzon
2026-07-31 23:27:23
(16 hours ago)
SSH brute-force / unauthorized login attempts observed against sovereign infrastructure.
Hits: 3. Co ...
show more
SSH brute-force / unauthorized login attempts observed against sovereign infrastructure.
Hits: 3. Confidence: 80.
Recent sample:
2026-07-31T23:26:01.319Z:
2026-07-31T23:25:27.023Z: Jul 31 23:25:26 the-os-sovereign sshd[3692580]: Invalid user orangepi from 104.252.175.42 port 39264
2026-07-31T23:24:55.745Z: Jul 31 23:24:55 the-os-sovereign sshd[3692511]: Invalid user admin from 104.252.175.42 port 52724
show less
Brute-Force
SSH