๐ฟ๐ฆ
conure.sh
2026-10-11 00:15:04
(14 hours ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 1s
Web App Attack
๐ฆ๐บ
foff
2026-10-11 00:09:49
(14 hours ago)
Source IP: 158.173.166.106 (NO/Glesys AB). Web application attack detected by OWASP CRS (local file ...
show more
Source IP: 158.173.166.106 (NO/Glesys AB). Web application attack detected by OWASP CRS (local file inclusion). Attack observed 2026-10-11T11:09:49+11:00.
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-11 00:06:06
(14 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-10-11 00:00:43
(14 hours ago)
ipoac.nl:80 158.173.166.106 - - [11/Oct/2026:02:00:41 +0200] ipoac.nl "GET /.git/config HTTP/1.1" 40 ...
show more
ipoac.nl:80 158.173.166.106 - - [11/Oct/2026:02:00:41 +0200] ipoac.nl "GET /.git/config HTTP/1.1" 403 1661 "-" "Go-http-client/1.1"
show less
Bad Web Bot
๐ต๐ฑ
lns.bz
2026-07-20 03:34:18
(2 months ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐ณ๐ฑ
Roderic
2026-07-20 02:54:37
(2 months ago)
(PERMBLOCK) 158.173.166.106 (NO/Norway/Oslo/Oslo/-/[redacted]) has had more than 4 temp blocks
Hacking
๐ซ๐ท
dynamix
2026-07-20 01:06:20
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ต๐ฑ
sefinek.net
2026-07-20 00:33:26
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from NO.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from NO.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
Roderic
2026-07-19 22:32:40
(2 months ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
Vegascosmetics
2026-07-19 22:24:34
(2 months ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ฒ๐ฝ
impra
2026-06-12 19:26:15
(3 months ago)
Detected 15 connection attempts.
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 16:12:49
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:12:42.303625 2026] [security2:error] [pid 20040:tid 20056] [client 158.173.166.106:52041] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||sonatro.io|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "sonatro.io"] [uri "/license.txt"] [unique_id "aiwv-jvQZNFqfDCFwv48zwAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-12 16:06:03
(3 months ago)
[FriJun1218:05:57.3567482026][security2:error][pid3950799:tid3950842][client158.173.166.106:0]ModSec ...
show more
[FriJun1218:05:57.3567482026][security2:error][pid3950799:tid3950842][client158.173.166.106:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:n\(\?:-stealth\|sauditor\|e\(\?:ssus\|etwork-services-auditor\)\|ikto\|map\)\|b\(\?:lack\?widow\|rutus\|ilbo\)\|web\(\?:inspec\|roo\)t\|p\(\?:mafind\|aros\|avuk\)\|cgichk\|jaascois\|\\\\\\\\.nasl\|metis\|w\(\?:ebtrendssecurityanalyzer\|hcc\|3af\\\\\\\\.sourceforge\\\\\\\\.net\)\|\\\\\\\\bzmeu\\\\\\\\b\|springenwerk\|...\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"184\"][id\"330034\"][rev\"14\"][msg\"Atomicorp.comWAFRules:UnauthorizedVulnerabilityScannerdetected\"][data\"paros\"][severity\"CRITICAL\"][hostname\"sisuconsulting.net\"][uri\"/license.txt\"][unique_id\"aiwuZdTmYz6U-bLNlYZEKwAAAEY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 15:30:00
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:29:54.380347 2026] [security2:error] [pid 19493:tid 19493] [client 158.173.166.106:33563] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||flic.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "flic.net"] [uri "/license.txt"] [unique_id "aiwl8gw96yaY5iB6zZYPLgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 14:03:00
(3 months ago)
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 158.173.166.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 10:02:55.603552 2026] [security2:error] [pid 15076:tid 15076] [client 158.173.166.106:65259] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||mlappa.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "mlappa.net"] [uri "/license.txt"] [unique_id "aiwRj00xN7g-sFjFmIgTXwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack