๐ช๐ธ
librebit
2026-07-26 09:03:26
(10 hours ago)
Brute force
Brute-Force
๐ฉ๐ช
CELOS-SOC
2026-07-25 16:30:06
(1 day ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
๐ฉ๐ช
eebh.hu
2026-07-24 14:46:47
(2 days ago)
Jul 24 16:46:30 mail dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 3 secs): user=<pe ...
show more
Jul 24 16:46:30 mail dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 3 secs): user=<[email protected] >, method=PLAIN, rip=169.150.201.32, lip=194.36.88.23, TLS: Connection closed, session=<tnEAcFxX79Splskg>
Jul 24 16:46:36 mail dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 6 secs): user=<[email protected] >, method=PLAIN, rip=169.150.201.32, lip=194.36.88.23, TLS: Connection closed, session=<dSAocFxXY4aplskg>
Jul 24 16:46:43 mail dovecot: pop3-login: Disconnected (auth failed, 1 attempts in 6 secs): user=<[email protected] >, method=PLAIN, rip=169.150.201.32, lip=194.36.88.23, TLS: Connection closed, session=<qReUcFxXm4Cplskg>
...
show less
Brute-Force
๐ฟ๐ฆ
conure
2026-07-24 12:07:32
(2 days ago)
csagent: score 20.1: 404 noise floor x2, secrets grab x2; 2 domain(s) in 8s
Web App Attack
๐ฉ๐ช
CELOS-SOC
2026-07-24 08:30:11
(2 days ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-24 08:05:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:05:14.359582 2026] [security2:error] [pid 3923:tid 3923] [client 169.150.201.32:48448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creartest.com"] [uri "/.git/index"] [unique_id "amMculqknvN3P0hBRGgA_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 07:37:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:37:11.381561 2026] [security2:error] [pid 1979454:tid 1979454] [client 169.150.201.32:58684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cortona.ws"] [uri "/.git/index"] [unique_id "amMWJzMydjYPGNBH7IW-OQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 07:16:42
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 07:06:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:06:31.140142 2026] [security2:error] [pid 3529796:tid 3529796] [client 169.150.201.32:57200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "connectigramme.com"] [uri "/.git/index"] [unique_id "amMO96lYFAZH5c2mv4imUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:02:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:02:13.156279 2026] [security2:error] [pid 3275665:tid 3275665] [client 169.150.201.32:49656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmcnow.com"] [uri "/.git/index"] [unique_id "amL_5VDfiZLuZTTFZtlaIQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:38:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:38:29.499808 2026] [security2:error] [pid 3801450:tid 3801450] [client 169.150.201.32:54400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clayrivers.com"] [uri "/.git/index"] [unique_id "amL6VdWBT4_MyZBHAZAB4AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-07-24 05:35:12
(2 days ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:14:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:14:44.079405 2026] [security2:error] [pid 3170966:tid 3170966] [client 169.150.201.32:33668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "circleinthesquare.org"] [uri "/.git/index"] [unique_id "amL0xD9VoOLJ5a3qrDPFvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 04:53:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.c ...
show more
(mod_security) mod_security (id:210492) triggered by 169.150.201.32 (unn-169-150-201-32.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:53:23.954859 2026] [security2:error] [pid 5030:tid 5030] [client 169.150.201.32:56172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christineohlman.net"] [uri "/.git/index"] [unique_id "amLvw0FQbv7hg6d8W1QkXgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-07-24 04:25:16
(2 days ago)
[24/Jul/2026:05:25:16.658378 +0100] amLpLNnqA0Jb_eMdCn6-TgAAAAc 169.150.201.32 54240 188.246.206.60 ...
show more
[24/Jul/2026:05:25:16.658378 +0100] amLpLNnqA0Jb_eMdCn6-TgAAAAc 169.150.201.32 54240 188.246.206.60 7081
[24/Jul/2026:05:25:17.219874 +0100] amLpLU61oT19VyPb4nlG3wAAAEs 169.150.201.32 54242 188.246.206.60 7081
...
show less
Brute-Force