๐บ๐ธ
jbettigole
2026-08-29 06:23:46
(1 day ago)
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/F ...
show more
MikroTik RouterOS: repeated connection attempts against non-public admin/service ports (SSH/Telnet/FTP/Winbox/API/WWW) triggering escalating 5m/15m/1h/1d blacklist
show less
Brute-Force
Hacking
๐ง๐ช
madeit
2026-08-21 00:06:19
(1 week ago)
Web App Attack
๐ง๐ช
voormedia
2026-08-06 04:53:27
(3 weeks ago)
Accessed trap at '/wp-admin/install.php'
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-16 00:08:34
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-06-16 17:37:46
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-13 18:04:54
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 14:04:49.013766 2026] [security2:error] [pid 25706:tid 25706] [client 162.158.94.218:13080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goodideagirl.com"] [uri "/.git/config"] [unique_id "ai2bwRqFU11KQLAqX06w2gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 13:04:03
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 09:03:58.774369 2026] [security2:error] [pid 17155:tid 17155] [client 162.158.94.218:13169] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ncogtrains.com"] [uri "/.git/config"] [unique_id "afNTPkPRT8bOpniyaTP-1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-14 05:40:42
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 01:40:37.297283 2026] [security2:error] [pid 4080740:tid 4080740] [client 162.158.94.218:12050] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pinman.com"] [uri "/.git/config"] [unique_id "ad3TVXs0DTrV0kPS72dfIwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-03 06:05:47
(4 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 21:51:36
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 17:51:29.360293 2026] [security2:error] [pid 21389:tid 21389] [client 162.158.94.218:11652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mark-et-ing-1llc.com"] [uri "/.git/HEAD"] [unique_id "ac7k4TgXXLHJUhKM-9l8UwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-04-02 17:41:07
(4 months ago)
Restricted File Access Attempt. Matched phrase "/.git/" at REQUEST_FILENAME. (930130-131)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 11:13:52
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:13:43.368497 2026] [security2:error] [pid 6868:tid 6868] [client 162.158.94.218:12825] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.reachpoint.com"] [uri "/.git/logs/HEAD"] [unique_id "acusZ49iHvbPOoZbd1z_2gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 00:06:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 162.158.94.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:06:28.560680 2026] [security2:error] [pid 29224:tid 29224] [client 162.158.94.218:9379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.martaaizenman.com"] [uri "/.git/HEAD"] [unique_id "acsQBJ7xz7XcxO6Duu5nsgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-03-30 10:52:07
(5 months ago)
[WAZUH] Access to sensitive configuration files detected.
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-03-29 22:12:38
(5 months ago)
Blocked Cloudflare Worker request. Pattern match "." at REQUEST_HEADERS:cf-worker. (5025-193)
Hacking