๐ธ๐ช
SkyDancer
2026-09-21 06:34:02
(1 week ago)
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blo ...
show more
Multiple intrusion attempts via http/https on known vulnerable url offsets. Attack automatically blocked by SkyDancer Ai(web-X).
show less
Hacking
Brute-Force
Anonymous
2026-09-19 20:10:57
(1 week ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
factor1
2026-09-19 16:13:43
(1 week ago)
CrowdSec at churndash Reports Abuse
Web App Attack
Anonymous
2026-09-19 15:46:30
(1 week ago)
(CT) IP 168.144.172.83 (-) found to have 14 connections; Ports: *; Direction: inout; Trigger: CT_LIM ...
show more
(CT) IP 168.144.172.83 (-) found to have 14 connections; Ports: *; Direction: inout; Trigger: CT_LIMIT; Logs: tcp: 168.144.172.83:56194 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56144 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56154 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:53128 -> 31.134.201.55:80 (TIME_WAIT)
tcp: 168.144.172.83:56134 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56116 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56178 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56170 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56192 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56160 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:57788 -> 31.134.201.55:443 (TIME_WAIT)
tcp: 168.144.172.83:56102 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56094 -> 31.134.201.55:443 (ESTABLISHED)
tcp: 168.144.172.83:56120 -> 31.134.201.55:443 (ESTABLISHED)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-19 15:06:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:06:35.746174 2026] [security2:error] [pid 1750:tid 1750] [client 168.144.172.83:54412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.jeffstamper.com"] [uri "/.git/config"] [unique_id "aq6k-xgSZcE0VobiyObD9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 13:57:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:57:08.743750 2026] [security2:error] [pid 5912:tid 5994] [client 168.144.172.83:38894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.geekshop.com"] [uri "/.git/config"] [unique_id "aq6UtDMrziptkTNt6OYGFQAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:41:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:41:19.930537 2026] [security2:error] [pid 26656:tid 26669] [client 168.144.172.83:44998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.despachosyoficinas.com"] [uri "/.git/config"] [unique_id "aq6C72Zt8owAKc-BET76vQAAAcE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-19 12:37:41
(1 week ago)
CrowdSec at atlas Reports Abuse
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-19 12:18:45
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
factor1
2026-09-19 11:27:52
(1 week ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:41:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:41:29.778902 2026] [security2:error] [pid 6915:tid 6915] [client 168.144.172.83:38110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.antoniorufino.com"] [uri "/.git/config"] [unique_id "aq5m2XnJBU5J0wffzE1c1QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-19 10:40:04
(1 week ago)
Bad behaviour
Web Spam
๐ซ๐ท
masterguru
2026-09-19 10:09:30
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 168.144.172.83 (AU/Australia/-): 2 in ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 168.144.172.83 (AU/Australia/-): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 08:58:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 168.144.172.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:58:29.439136 2026] [security2:error] [pid 25698:tid 25698] [client 168.144.172.83:58604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fsmfl.com"] [uri "/.git/config"] [unique_id "aq5Ote8rNeSi8qamq_IBMgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-19 06:00:05
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH