A web attack was detected from 166.88.83.126 (United States) against 52.215.230.232 (Git Variable Sc ...
show moreA web attack was detected from 166.88.83.126 (United States) against 52.215.230.232 (Git Variable Scan).
show less
This IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to ...
show moreThis IP was detected by CrowdSec triggering crowdsecurity/suricata-major-severity(ET INFO Request to Hidden Environment File - Inbound). Ip 166.88.83.126 performed 'crowdsecurity/suricata-major-severity' (1 events over 0s) at 2025-10-09 23:57:03.65332244 +0000 UTC
show less
[Sun Sep 14 13:52:33.122336 2025] [security2:error] [pid 1738940:tid 140266892576448] [client 166.88 ...
show more[Sun Sep 14 13:52:33.122336 2025] [security2:error] [pid 1738940:tid 140266892576448] [client 166.88.83.126:57101] ModSecurity: Access denied with code 403 (phase 1). Match of "ipMatch 103.166.156.58" against "REMOTE_ADDR" required. [file "/etc/modsecurity/coreruleset-4.16.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "372"] [id "440006"] [msg "Connection Close Header"] [data " Matched Data ARGS charset: - Matched Data TX.1: found within Content-Type multipart form Matched Data: close found within REMOTE_ADDR: 166.88.83.126 request_line = GET /index.php/prakiraan-musim/267-prakiraan-musim-hujan/prakiraan-awal-musim-hujan/prakiraan-awal-musim-hujan-propinsi-jawa-timur HTTP/1.1 Request URI RAW = /index.php/prakiraan-musim/267-prakiraan-musim-hujan/prakiraan-awal-musim-hujan/prakiraan-awal-musim-hujan-propinsi-jawa-timur Request Basename = prakiraan-awal-musim-hujan-propinsi-ja..."] [hostname "staklim-malang.info"] [uri "/index.php/prakiraan-musim/267-prakiraan-musim-hujan/praki
...
show less
Attempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" ...
show moreAttempt to access invalid virtual host name (###.###.###.###). Typically used to access "internal" resources improperly exposed externally and "protected" only by a lack of external DNS resolution.
166.88.83.126 - - [21/May/2025:19:24:40 +0000] "GET /.env HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.5845.140 Safari/537.36" "-"
show less