๐ธ๐ฆ
BenTahily
2026-10-07 07:01:47
(6 hours ago)
[moaem.com] Banned by Fail2Ban jails: nginx-credential-theft. Automated report.
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-10-07 02:07:41
(11 hours ago)
Repeated exploit attempts, for example: //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php //vendo ...
show more
Repeated exploit attempts, for example: //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php /eval-stdin.php (HTTP/1.1 port 443)
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:50:44
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:50:37.560551 2026] [security2:error] [pid 3006440:tid 3006466] [client 170.64.182.228:39436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mojodelicatesse.com.oplconnect.com"] [uri "/.git/config"] [unique_id "asWlbdJ7xxyqxnGaVsgvgwAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tamsy
2026-10-07 01:22:52
(12 hours ago)
HTTPD - 4xx scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:21:49
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:21:43.818597 2026] [security2:error] [pid 12504:tid 12504] [client 170.64.182.228:34536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mohsep-eg.com"] [uri "/.git/config"] [unique_id "asWep0HgazEj2EqoU8vDSgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-07 00:33:05
(13 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 00:29:18
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 20:29:14.772587 2026] [security2:error] [pid 1135:tid 1135] [client 170.64.182.228:42554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moellerlaw.com"] [uri "/.git/config"] [unique_id "asWSWkW_HtFVeTsEYpLmDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 00:25:03
(13 hours ago)
suspicious request in access.log
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-07 00:18:41
(13 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 170 ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 170.64.182.228 - - \[07/Oct/2026:02:18:27 +0200\] "GET /.git/config HTTP/1.1" 301 537 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/132.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Zundapper
2026-10-07 00:16:02
(13 hours ago)
170.64.182.228 - - [07/Oct/2026:02:16:00 +0200] "GET //static/lib/jquery-file-upload/server/php/ HTT ...
show more
170.64.182.228 - - [07/Oct/2026:02:16:00 +0200] "GET //static/lib/jquery-file-upload/server/php/ HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
170.64.182.228 - - [07/Oct/2026:02:16:00 +0200] "GET //jquery.filer/php/readme.txt HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
170.64.182.228 - - [07/Oct/2026:02:16:00 +0200] "GET //file-manager/initialize HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
170.64.182.228 - - [07/Oct/2026:02:16:00 +0200] "GET //assets/vendor/jquery.filer/php/readme.txt HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
170.64.182.228 - - [07/Oct/2026:02:16:01 +0200] "GET //plugins/jquery.filer/php/readme.txt HTTP/1.1"
...
show less
Web App Attack
Port Scan
๐ฉ๐ช
4server
2026-10-07 00:13:00
(13 hours ago)
[WedOct0702:12:55.5145822026][security2:error][pid166139:tid166237][client170.64.182.228:0]ModSecuri ...
show more
[WedOct0702:12:55.5145822026][security2:error][pid166139:tid166237][client170.64.182.228:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"modularss.com\"][uri\"/.git/config\"][unique_id\"asWOhwS7b3eUcQRij20Y_wAAAQE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
JustMeHere
2026-10-07 00:08:08
(13 hours ago)
[Tue Oct 06 20:08:02.480847 2026] [security2:error] [pid 1249:tid 1281] [client 170.64.182.228:39058 ...
show more
[Tue Oct 06 20:08:02.480847 2026] [security2:error] [pid 1249:tid 1281] [client 170.64.182.228:39058] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mods.yorknation.com"] [uri "/.git/config"] [unique_id "asWNYpGlSUsbYuhhFIAgJgAAAMQ"]
...
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-07 00:03:13
(13 hours ago)
excessive HTTP 404 errors
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 23:31:43
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:31:39.166124 2026] [security2:error] [pid 11641:tid 11641] [client 170.64.182.228:58160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modernsalesforce.wholesalelivelobsters.com"] [uri "/.git/config"] [unique_id "asWE21fUUd6NE4X7-kKZIwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 23:00:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.182.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 19:00:41.201887 2026] [security2:error] [pid 4751:tid 4755] [client 170.64.182.228:55142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moderncabinetcorp.com"] [uri "/.git/config"] [unique_id "asV9mQwkDBcYvGA9WJrieAAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack