🇺🇸
TPI-Abuse
2026-09-05 05:19:52
(1 day ago)
(mod_security) mod_security (id:210801) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 01:19:45.389936 2026] [security2:error] [pid 32084:tid 32084] [client 172.178.119.118:4120] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "grabber" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.unitymaine.org|F|2"] [data "electiondatagrabber/0.1 (+academic election research)"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.unitymaine.org"] [uri "/town-clerk/pages/elections"] [unique_id "apumcVUhfdvRzmZzFyG9iwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-06-23 11:50:31
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
KPS
2026-06-14 10:01:02
(2 months ago)
PortscanM
Port Scan
🇺🇸
TPI-Abuse
2026-06-14 08:32:55
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 04:32:47.925118 2026] [security2:error] [pid 29092:tid 29092] [client 172.178.119.118:10049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.155"] [uri "/.git/HEAD"] [unique_id "ai5nL2CRjun_poz5NeNt_QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-14 07:52:07
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:52:02.064120 2026] [security2:error] [pid 13792:tid 13792] [client 172.178.119.118:9816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.243"] [uri "/.git/HEAD"] [unique_id "ai5doue9HNqxTXPbsmV2MgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
Threat.live
2026-06-14 07:50:03
(2 months ago)
Suspicious Connection Attempts
Brute-Force
🇫🇮
[email protected]
2026-06-14 07:03:22
(2 months ago)
Attack attempt against Interwebbi servers; *Port Scan* detected from 172.178.119.118 (US/United Stat ...
show more
Attack attempt against Interwebbi servers; *Port Scan* detected from 172.178.119.118 (US/United States/-). 5 hits in the last 140 seconds; IP: 172.178.119.118; Ports: *; Direction: 0; Trigger: PS_LIMIT;
show less
Brute-Force
🇩🇪
ITSNF
2026-06-14 06:35:03
(2 months ago)
Blocked by os-abuseipdb; 10 hits, proto=tcp, ports=2077,2078,2082,2083,2086,2087,2095,2096,443,80
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-06-14 06:03:12
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 172.178.119.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 02:03:06.371579 2026] [security2:error] [pid 27278:tid 27278] [client 172.178.119.118:9894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.14"] [uri "/.git/HEAD"] [unique_id "ai5EGuOo583iEJaDPHoOkwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
MPL
2026-06-14 04:54:40
(2 months ago)
tcp port scan (10 or more attempts)
Port Scan
🇺🇸
Axel
2026-06-14 04:30:06
(2 months ago)
Blocked by UFW on MVI [2083/tcp] | SPT: 9998 | TTL: 48 | LEN: 60 | TOS: 0x00 • Reported by: github.c ...
show more
Blocked by UFW on MVI [2083/tcp] | SPT: 9998 | TTL: 48 | LEN: 60 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇩🇪
ghostwarriors
2026-06-14 03:50:37
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Rom74
2026-06-14 03:29:10
(2 months ago)
[Sun Jun 14 05:29:08.727693 2026] [security2:error] [pid 2282781:tid 131878927353536] [client 172.17 ...
show more
[Sun Jun 14 05:29:08.727693 2026] [security2:error] [pid 2282781:tid 131878927353536] [client 172.178.119.118:8582] [client 172.178.119.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "86.205.229.132"] [uri "/.env.production"] [unique_id "ai4gBObTVjN0OMehWKdJuwAAAMY"]
[Sun Jun 14 05:29:09.832302 2026] [security2:error] [pid 2282758:tid 131878287820480] [client 172.178.119.118:8593] [client 172.178.119.118] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Scor
...
show less
Web App Attack
🇸🇪
nekopavel
2026-06-14 03:28:14
(2 months ago)
172.178.119.118 - - [14/Jun/2026:05:28:06 +0200]"GET /.git/HEAD HTTP/1.1" 301 162"-" 78.69.8.25 "Moz ...
show more
172.178.119.118 - - [14/Jun/2026:05:28:06 +0200]"GET /.git/HEAD HTTP/1.1" 301 162"-" 78.69.8.25 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0""0.000" "-""Washington" "US"
172.178.119.118 - - [14/Jun/2026:05:28:07 +0200]"GET /.git/config HTTP/1.1" 301 162"-" 78.69.8.25 "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)""0.000" "-""Washington" "US"
172.178.119.118 - - [14/Jun/2026:05:28:11 +0200]"GET /.env.save HTTP/1.1" 301 162"-" 78.69.8.25 "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36""0.000" "-""Washington" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇯🇵
demonsword
2026-05-06 06:47:58
(4 months ago)
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was ...
show more
Detected by SentinelX honeypot: sent HTTP CONNECT request probing for an open proxy. Connection was hijacked and held in a tarpit to slow down the scan. Probed target: 1.1.1.1:443
show less
Open Proxy
Port Scan