🇫🇷
sthoyer.de
2026-08-26 20:42:59
(2 weeks ago)
Aug 26 22:42:58 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd: ...
show more
Aug 26 22:42:58 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=172.203.30.212 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=23149 DF PROTO=TCP SPT=21595 DPT=2096 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 26 22:42:58 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=172.203.30.212 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=50 ID=61410 DF PROTO=TCP SPT=21569 DPT=8080 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 26 22:42:58 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=172.203.30.212 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=22025 DF PROTO=TCP SPT=21582 DPT=2087 WINDOW=64240 RES=0x00 SYN URGP=0
Aug 26 22:42:58 sthoyer kernel: [IPTables-Dropped-I] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=172.203.30.212 DST=173.212.223.67 LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=33437 DF PROTO=TCP SPT=21600 DPT=2083 WI
...
show less
Port Scan
🇩🇪
nyt
2026-08-26 20:33:23
(2 weeks ago)
Sensitive File Probe, Accessing sensitive .git directory logs
Web App Attack
🇮🇪
AutosOnShow
2026-08-26 19:05:05
(2 weeks ago)
blocked for webapp attack | path requested: /.env | seen at 2026-08-26 19:04:46.851 |
Web App Attack
🇸🇪
SkyDancer
2026-07-19 21:11:00
(1 month ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-06-29 05:17:01
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 01:16:57.089034 2026] [security2:error] [pid 6482:tid 6482] [client 172.203.30.212:19719] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.227"] [uri "/.git/HEAD"] [unique_id "akH_yT00j0byFTaAUDfAXQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Mark--
2026-06-26 11:27:34
(2 months ago)
Unauthorized connection attempt detected port 8080
Hacking
🇺🇸
MPL
2026-06-26 09:31:05
(2 months ago)
tcp port scan (8 or more attempts)
Port Scan
Anonymous
2026-06-26 06:52:12
(2 months ago)
WordPress Sensitive System Files Information Disclosure.
Hacking
🇺🇸
TPI-Abuse
2026-06-26 06:37:43
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 02:37:37.258765 2026] [security2:error] [pid 14904:tid 14904] [client 172.203.30.212:22147] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.23"] [uri "/.git/HEAD"] [unique_id "aj4eMTImoGpTxrYgtEypbwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇭
Sawasdee
2026-06-26 06:36:08
(2 months ago)
Unwanted checking 80 or 443 port
...
Bad Web Bot
Anonymous
2026-06-26 05:44:05
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
🇺🇸
TPI-Abuse
2026-06-26 04:37:41
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.203.30.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 00:37:34.722751 2026] [security2:error] [pid 8335:tid 8335] [client 172.203.30.212:21537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.18"] [uri "/.git/HEAD"] [unique_id "aj4CDr4wYpTDLZDFg4wVRAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gu-alvareza
2026-06-03 07:05:13
(3 months ago)
HTPasswd.Access
Brute-Force
🇷🇸
Scan
2026-06-03 02:31:38
(3 months ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
🇩🇪
ghostwarriors
2026-06-02 23:20:17
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack