๐ซ๐ท
tecnicorioja
2026-08-23 22:01:50
(1 day ago)
(Mod_security)
Web App Attack
Brute-Force
Bad Web Bot
Anonymous
2026-08-23 22:00:37
(1 day ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐ฎ๐น
CoreTech srl
2026-08-23 21:53:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-23 23:50:05,974 fail2ban.filter [1496]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-23 23:50:05,974 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 120.48.142.55 - 2026-08-23 23:50:05cloudlinux2 fail2ban: 2026-08-23 23:50:46,071 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 180.153.236.114 - 2026-08-23 23:50:46cloudlinux2 fail2ban: 2026-08-23 23:50:50,890 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 180.153.236.45 - 2026-08-23 23:50:50cloudlinux2 fail2ban: 2026-08-23 23:51:12,189 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 170.64.205.23 - 2026-08-23 23:51:12cloudlinux2 fail2ban: 2026-08-23 23:51:13,168 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 170.64.205.23 - 2026-08-23 23:51:13cloudlinux2 fail2ban: 2026-08-23 23:51:46,817 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 46.184.19.23 - 2026-08-23 23:51:46cloudlinux2 fail2ban: 2026-08-23 23:51:57,140 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 46.184.19.23 - 2026-08-23 23:5
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-23 18:50:22
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 17:55:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 13:55:06.140511 2026] [security2:error] [pid 24716:tid 24716] [client 170.64.205.23:49734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solve4this.com"] [uri "/.git/config"] [unique_id "aosz-pMTIXb4prt4CE3krAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-23 16:24:28
(1 day ago)
[Mon Aug 24 02:24:27.793565 2026] [security2:error] [pid 452191] [client 170.64.205.23:45654] [clien ...
show more
[Mon Aug 24 02:24:27.793565 2026] [security2:error] [pid 452191] [client 170.64.205.23:45654] [client 170.64.205.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "aoseu1bxIuYe6NDO6M9CGAAAAAE"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 15:15:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:15:13.063330 2026] [security2:error] [pid 28708:tid 28708] [client 170.64.205.23:59912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybarrera.com"] [uri "/.git/config"] [unique_id "aosOgQN59x9SlCgBzLdtSQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-23 12:52:16
(1 day ago)
[Sun Aug 23 22:52:15.159221 2026] [security2:error] [pid 433827] [client 170.64.205.23:34860] [clien ...
show more
[Sun Aug 23 22:52:15.159221 2026] [security2:error] [pid 433827] [client 170.64.205.23:34860] [client 170.64.205.23] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "aors_7esiHEmiZbOXHx8AAAAAAQ"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:34:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:34:29.693410 2026] [security2:error] [pid 9425:tid 9425] [client 170.64.205.23:37336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mindbodyrestored.com"] [uri "/.git/config"] [unique_id "aoro1dysq3I4ypz8-kIvagAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-23 12:11:24
(1 day ago)
csagent: score 20.0: secrets grab x2, 404 noise floor x2; 2 domain(s) in 9s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:46:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:46:54.163378 2026] [security2:error] [pid 22670:tid 22670] [client 170.64.205.23:59040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rotarymagnetics.com"] [uri "/.git/config"] [unique_id "aordrl5-TLQ-Hrw35JTUSgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sojan
2026-08-23 11:46:52
(1 day ago)
170.64.205.23 - - [23/Aug/2026:11:09:26 +0200] "GET /.git/config HTTP/1.1" 502 559 "-" "Mozilla/5.0 ...
show more
170.64.205.23 - - [23/Aug/2026:11:09:26 +0200] "GET /.git/config HTTP/1.1" 502 559 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.205.23 - - [23/Aug/2026:11:09:27 +0200] "GET /.git/config HTTP/1.1" 404 1678 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.205.23 - - [23/Aug/2026:13:46:52 +0200] "GET /.git/config HTTP/1.1" 502 559 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:13:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:13:27.070876 2026] [security2:error] [pid 20614:tid 20614] [client 170.64.205.23:55238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "livinghopehighschool.org"] [uri "/.git/config"] [unique_id "aorV1_Stw23Aem2xyWya7wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 10:37:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:17:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.205.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:17:20.239803 2026] [security2:error] [pid 15255:tid 15255] [client 170.64.205.23:37378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "winformation.us"] [uri "/.git/config"] [unique_id "aoq6oJURFBC5DjhcUcEC5wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack