๐ฟ๐ฆ
conure
2026-07-23 12:11:37
(1 day ago)
csagent: score 18.8: secrets grab x2, 404 noise floor x1; 2 domain(s) in 26s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:36:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:36:03.264310 2026] [security2:error] [pid 2240356:tid 2240356] [client 167.82.167.21:31276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.swcbsa.org"] [uri "/.git/HEAD"] [unique_id "amHggz7NPCWyeDusTntopQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:19:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:19:17.072353 2026] [security2:error] [pid 2413478:tid 2413478] [client 167.82.167.21:63352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.unitymaine.org"] [uri "/.git/HEAD"] [unique_id "amHclUszx2N_0VYXGNg3uQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-07-23 09:08:41
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:01:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:01:35.853289 2026] [security2:error] [pid 28075:tid 28075] [client 167.82.167.21:40860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centerofhopefl.com.tribecalledfamilypodcast.org"] [uri "/.git/HEAD"] [unique_id "amHYb0YBiXrwuNFlUASsfwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 08:38:54
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 04:38:50.190127 2026] [security2:error] [pid 2779406:tid 2779406] [client 167.82.167.21:44422] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "auranet.cescfoundation.org"] [uri "/.git/HEAD"] [unique_id "amHTGj4TlMS3bIgv4Wp-bQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-07-23 08:06:02
(2 days ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 07:56:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 03:56:17.414302 2026] [security2:error] [pid 10807:tid 10807] [client 167.82.167.21:26360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.smokehouseeatery.ca"] [uri "/.git/HEAD"] [unique_id "amHJIZK7dhvZCa2pMJPo2QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 04:32:09
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-07-23 04:20:54
(2 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-07-23 03:18:02
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 00:05:01
(2 days ago)
suspicious request in access.log
Web App Attack
๐ง๐ท
borbolla
2026-07-23 00:00:33
(2 days ago)
Automated web credential/secret scanner blocked by Fail2Ban. Probed: "GET /.git/HEAD HTTP/1.1"
Web App Attack
Bad Web Bot
Anonymous
2026-07-22 23:59:54
(2 days ago)
167.82.167.21 - - [22/Jul/2026:20:59:53 -0300] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Mac ...
show more
167.82.167.21 - - [22/Jul/2026:20:59:53 -0300] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-07-22 23:27:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 167.82.167.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:26:54.282656 2026] [security2:error] [pid 1500986:tid 1500986] [client 167.82.167.21:38476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.arts4health.org"] [uri "/.git/HEAD"] [unique_id "amFRvmcH8rBw3xXrpWnybgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack