๐ณ๐ฑ
Eric
2026-07-31 03:19:44
(9 minutes ago)
[Fri Jul 31 03:19:45.069599 2026] [security2:error] [pid 3020370:tid 3020370] [client 162.243.3.220: ...
show more
[Fri Jul 31 03:19:45.069599 2026] [security2:error] [pid 3020370:tid 3020370] [client 162.243.3.220:52186] [client 162.243.3.220] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:Host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "amwUUUgSUDh2nyCqG3xG7wAAABU"]
[Fri Jul 31 03:19:45.070072 2026] [security2:error] [pid 3020370:tid 3020370] [client 162.243.3.220:52186] [client 162.243.3.220] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.con
...
show less
Hacking
Web App Attack
๐ฆ๐น
Starburst SysOp Team
2026-07-31 03:11:31
(18 minutes ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-vie6-1)
Hacking
Bad Web Bot
Anonymous
2026-07-31 03:02:02
(27 minutes ago)
Bad Web Bot
๐ฉ๐ช
mygcode.de
2026-07-31 02:54:31
(35 minutes ago)
Scanning for Exploits
Bad Web Bot
๐ฉ๐ช
pcpiefke
2026-07-31 02:35:08
(54 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 162.243.3.220 (US/United States/-)
SQL Injection
๐ฎ๐น
madaello
2026-07-31 02:29:38
(59 minutes ago)
162.243.3.220 - - [31/Jul/2026:04:29:32 +0200] "GET /.git/HEAD HTTP/1.1" 301 4671 "-" "Mozilla/5.0 ( ...
show more
162.243.3.220 - - [31/Jul/2026:04:29:32 +0200] "GET /.git/HEAD HTTP/1.1" 301 4671 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
162.243.3.220 - - [31/Jul/2026:04:29:32 +0200] "GET /.git/config HTTP/1.1" 301 4675 "-" "Mozilla/5.0 (compatible; Google-CloudVertexBot; +https://cloud.google.com/vertex-ai-bot)"
162.243.3.220 - - [31/Jul/2026:04:29:32 +0200] "GET / HTTP/1.1" 301 4654 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
162.243.3.220 - - [31/Jul/2026:04:29:37 +0200] "GET /js/jquery-3.2.1.slim.min.js HTTP/1.1" 301 642 "-" "Mozilla/5.0 (compatible; OAI-SearchBot/1.3; +https://openai.com/searchbot)"
...
show less
Hacking
๐ฎ๐น
Inartis
2026-07-31 02:26:45
(1 hour ago)
162.243.3.220 - - [31/Jul/2026:04:26:43 +0200] "GET /.git/config HTTP/1.1" 404 5513 "-" "Mozilla/5.0 ...
show more
162.243.3.220 - - [31/Jul/2026:04:26:43 +0200] "GET /.git/config HTTP/1.1" 404 5513 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
162.243.3.220 - - [31/Jul/2026:04:26:44 +0200] "GET /.env HTTP/1.1" 404 403 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
162.243.3.220 - - [31/Jul/2026:04:26:44 +0200] "GET /.env.local HTTP/1.1" 404 5513 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-31 02:02:22
(1 hour ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฉ๐ช
LRob
2026-07-31 00:55:26
(2 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths
Hacking
Anonymous
2026-07-31 00:45:38
(2 hours ago)
162.243.3.220 - - [31/Jul/2026:00:45:38 +0000] "GET /.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 (compat ...
show more
162.243.3.220 - - [31/Jul/2026:00:45:38 +0000] "GET /.env HTTP/1.1" 403 153 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "-" "91.98.135.170"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-31 00:18:36
(3 hours ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-07-30 23:44:34
(3 hours ago)
Aggressive web search of vulnerable pages: /.env.local /.env /.env.test /.env.backup /app/.env /.env ...
show more
Aggressive web search of vulnerable pages: /.env.local /.env /.env.test /.env.backup /app/.env /.env.bak /.env.prod /.env.production /backend/. ...
show less
Web App Attack
๐ช๐ธ
alferez
2026-07-30 23:43:21
(3 hours ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-30 23:09:38
(4 hours ago)
Requested unexistent endpoint (Wordpress login, etc.)
Web App Attack
Anonymous
2026-07-30 22:50:56
(4 hours ago)
162.243.3.220 - - [31/Jul/2026:00:50:48 +0200] "GET / HTTP/1.1" 403 4414 "-" "CCBot/2.0 (https://com ...
show more
162.243.3.220 - - [31/Jul/2026:00:50:48 +0200] "GET / HTTP/1.1" 403 4414 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack