๐บ๐ธ
TPI-Abuse
2026-08-25 18:22:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.203.195.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.203.195.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:21:58.082104 2026] [security2:error] [pid 12220:tid 12220] [client 172.203.195.10:40167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.247"] [uri "/.git/HEAD"] [unique_id "ao3dRgrynUysHJdHodG0hwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 18:17:51
(1 day ago)
denied traffic to a non-approved destination port. destination port 2095.
Port Scan
๐ฉ๐ช
bancix
2026-08-25 17:44:23
(1 day ago)
Heimdall NIDS: Automatic ban triggered. Reason: PORT_SWEEP_DETECTED (5 porte uniche in 10s)
Port Scan
๐ฌ๐ง
Aetherweb Ark
2026-08-25 17:11:45
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.203.195.10 (US/United States/-): N in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 172.203.195.10 (US/United States/-): N in the last X secs
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-25 17:07:49
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Hary74656
2026-08-25 16:46:40
(1 day ago)
[Tue Aug 25 18:46:37.176184 2026] [security2:error] [pid 193304:tid 193451] [client 172.203.195.10:4 ...
show more
[Tue Aug 25 18:46:37.176184 2026] [security2:error] [pid 193304:tid 193451] [client 172.203.195.10:40863] [client 172.203.195.10] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/usr/share/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/head"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "78.46.107.184"] [uri "/.git/HEAD"] [unique_id "ao3G7C9aBGhor4zF9SN8CgAAA-c"]
[Tue Aug 25 18:46:37.874523 2026] [security2:error] [pid 192646:tid 192776] [client 172.203.195.10:40840] [client 172.203.195.10] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "/.git/" at REQUEST_FILENAME. [file "/u
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:42:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.203.195.10 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.203.195.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:41:58.102255 2026] [security2:error] [pid 19574:tid 19574] [client 172.203.195.10:40896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.70"] [uri "/.git/HEAD"] [unique_id "ao2ptigMEtSQe2Xp8TqF4QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2026-08-25 14:35:20
(1 day ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-25 21:50:25
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-06-25 21:27:55
(2 months ago)
172.203.195.10 - - [25/Jun/2026:21:27:53 +0000] "GET http://ipv4.download.thinkbroadband.com/1MB.zip ...
show more
172.203.195.10 - - [25/Jun/2026:21:27:53 +0000] "GET http://ipv4.download.thinkbroadband.com/1MB.zip HTTP/1.1" 403 477 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
172.203.195.10 - - [25/Jun/2026:21:27:53 +0000] "GET http://speedtest.tele2.net/1MB.zip HTTP/1.1" 403 464 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
Rayulcifer
2026-06-25 21:26:14
(2 months ago)
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "GET http://ipv4.download.thinkbroadband.com/1MB.zip ...
show more
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "GET http://ipv4.download.thinkbroadband.com/1MB.zip HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "GET http://cachefly.cachefly.net/200mb.test HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "GET http://speedtest.tele2.net/1MB.zip HTTP/1.1" 403 363 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "CONNECT proof.ovh.net:443 HTTP/1.1" 403 344 "-" "-"
172.203.195.10 - - [25/Jun/2026:16:26:13 -0500] "CONNECT speed.hetzner.de:443 HTTP/1.1" 403 344 "-" "-"
...
show less
Open Proxy
Port Scan
Hacking
Web App Attack
SSH