Anonymous
2026-09-02 16:12:02
(19 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐ซ๐ท
SpaceHost-Server
2026-08-31 12:31:46
(2 days ago)
Brute-Force
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-31 12:08:05
(2 days ago)
csagent: score 24.7: 404 noise floor x13, secrets grab x1, phpunit eval-stdin RCE x1; 1 domain(s) in ...
show more
csagent: score 24.7: 404 noise floor x13, secrets grab x1, phpunit eval-stdin RCE x1; 1 domain(s) in 1s
show less
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-31 05:13:59
(3 days ago)
63 attacks on PHP URLs, VC URLs, Alfa URLs:
GET //plugins/responsive_filemanager/filemanager/dialog. ...
show more
63 attacks on PHP URLs, VC URLs, Alfa URLs:
GET //plugins/responsive_filemanager/filemanager/dialog.php HTTP/1.1
GET /.git/config HTTP/1.1
POST //alfacgiapi/perl.alfa HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-30 22:56:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:56:37.509686 2026] [security2:error] [pid 11868:tid 11868] [client 152.42.225.190:33594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apartfragamaia.com"] [uri "/.git/config"] [unique_id "apS1JVn_7g-oKUr7f0JOlAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 20:05:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:05:10.479953 2026] [security2:error] [pid 28406:tid 28406] [client 152.42.225.190:57842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anywherecamera.com"] [uri "/.git/config"] [unique_id "apSM9lAiKvKZQtjmoomLbwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 18:33:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:33:39.377151 2026] [security2:error] [pid 5640:tid 5640] [client 152.42.225.190:45906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anxietyquest.com"] [uri "/.git/config"] [unique_id "apR3g1RhhPd3a-XwMUBA3QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 18:16:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:16:08.715936 2026] [security2:error] [pid 1743:tid 1743] [client 152.42.225.190:57950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anus.deubellzebub.com"] [uri "/.git/config"] [unique_id "apRzaFg79ccoNEJb5NjGhAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-30 18:00:21
(3 days ago)
2026/08/30 18:00:19 [error] 912516#912516: *537574541 access forbidden by rule, client: 152.42.225.1 ...
show more
2026/08/30 18:00:19 [error] 912516#912516: *537574541 access forbidden by rule, client: 152.42.225.190, server: antzcapital.com, request: "GET //static/lib/jquery-file-upload/server/php/ HTTP/1.1", host: "antzcapital.com"
2026/08/30 18:00:19 [error] 912516#912516: *537574541 access forbidden by rule, client: 152.42.225.190, server: antzcapital.com, request: "GET //assets/admin/bower_components/jquery.filer/php/readme.txt HTTP/1.1", host: "antzcapital.com"
2026/08/30 18:00:19 [error] 912516#912516: *537574541 access forbidden by rule, client: 152.42.225.190, server: antzcapital.com, request: "GET //assets/plugins/jQuery-File-Upload/server/php/ HTTP/1.1", host: "antzcapital.com"
...
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-30 18:00:00
(3 days ago)
csagent: score 24.7: 404 noise floor x13, phpunit eval-stdin RCE x1, secrets grab x1; 1 domain(s) in ...
show more
csagent: score 24.7: 404 noise floor x13, phpunit eval-stdin RCE x1, secrets grab x1; 1 domain(s) in 1s
show less
Web App Attack
๐ฎ๐น
Inartis
2026-08-30 17:29:03
(3 days ago)
152.42.225.190 - - [30/Aug/2026:19:29:02 +0200] "GET /.git/config HTTP/1.1" 403 157 "-" "Mozilla/5.0 ...
show more
152.42.225.190 - - [30/Aug/2026:19:29:02 +0200] "GET /.git/config HTTP/1.1" 403 157 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-30 17:25:54
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-30 17:17:47
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-08-30 16:55:02
(3 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 16:51:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 152.42.225.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 12:51:14.162974 2026] [security2:error] [pid 23284:tid 23284] [client 152.42.225.190:38666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "antiradares.portalvasco.com"] [uri "/.git/config"] [unique_id "apRfgga5viem3NBV-kGlrwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack