πΊπΈ
MatCat
2026-07-19 17:05:04
(20 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
Anonymous
2026-07-19 15:10:05
(22 hours ago)
(PERMBLOCK) 142.248.80.197 (US/United States/-) has had more than 4 temp blocks in the last 86400 se ...
show more
(PERMBLOCK) 142.248.80.197 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
π³π±
Mangelot Hosting
2026-07-19 14:48:59
(22 hours ago)
(modsecurity) srv104 ModSecurity 142.248.80.197 (US/United States/-): 10 in the last 3600 secs; Port ...
show more
(modsecurity) srv104 ModSecurity 142.248.80.197 (US/United States/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-07-19 13:45:38
(23 hours ago)
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:13:45:35 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:13:45:35 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:13:45:35 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:13:45:35 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:13:45:35 +0000] "GET /.env.development HTTP/1.1"
show less
Port Scan
π©πͺ
Blexyel
2026-07-19 13:25:11
(1 day ago)
142.248.80.197 - - [19/Jul/2026:15:25:10 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
142.248.80.197 - - [19/Jul/2026:15:25:10 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-19 12:40:39
(1 day ago)
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:12:40:35 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:12:40:35 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:12:40:35 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:12:40:35 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:12:40:35 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
πΏπ¦
conure
2026-07-19 11:50:02
(1 day ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
π·πΊ
DZBOT
2026-07-19 10:41:32
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-07-19 09:28:11
(1 day ago)
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Po ...
show more
(caddyscan) Scanner path probe from 142.248.80.197 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:09:28:09 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:09:28:09 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:09:28:09 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:09:28:09 +0000] "GET /.env.development HTTP/1.1"
[REDACTED] 200 2627 142.248.80.197 - - [19/Jul/2026:09:28:09 +0000] "GET /.env.production HTTP/1.1"
show less
Port Scan
π«π·
dynamix
2026-07-19 09:14:40
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 09:07:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 05:07:17.774667 2026] [security2:error] [pid 29183:tid 29183] [client 142.248.80.197:51274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.merlinaerospace.com"] [uri "/.git/HEAD"] [unique_id "alyTxcs93TtMv0C6gdcYsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 01:32:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 21:32:10.369024 2026] [security2:error] [pid 14046:tid 14046] [client 142.248.80.197:39644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "envirotreecare.com"] [uri "/.git/HEAD"] [unique_id "alwpGiIorjeuhdr7Fpjw9wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
juguemosalacarioca.com
2026-07-19 00:41:38
(1 day ago)
Multiple HTTP calls attempting to GET resources using common API calls or formats on port 8080
Web App Attack
π¨π
backslash
2026-07-19 00:18:14
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-18 23:55:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 142.248.80.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 19:55:06.479938 2026] [security2:error] [pid 24032:tid 24032] [client 142.248.80.197:36134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eurosoni.emisoni.com"] [uri "/.git/HEAD"] [unique_id "alwSWrXch9i4vYy9lGCjAgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack