๐ฏ๐ต
S.O.B.A. Dev.
2026-09-26 21:11:55
(21 hours ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐ง๐ช
madeit
2026-09-21 20:28:21
(5 days ago)
Web App Attack
Anonymous
2026-09-14 08:48:18
(1 week ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ซ๐ท
dynamix
2026-09-12 18:21:23
(2 weeks ago)
Multiple WAF Violations
Web App Attack
๐ง๐ช
madeit
2026-09-08 10:28:38
(2 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-28 20:13:17
(4 weeks ago)
Web App Attack
๐ง๐ช
madeit
2026-08-21 02:15:23
(1 month ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 22:56:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 18:55:58.115130 2026] [security2:error] [pid 24921:tid 24921] [client 172.68.138.183:13034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.michaelholdaway.com"] [uri "/.git/HEAD"] [unique_id "aoORfuxmh0qzWtI20wbX1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 05:21:50
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:21:43.642180 2026] [security2:error] [pid 26408:tid 26423] [client 172.68.138.183:10109] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abney.info"] [uri "/.git/config"] [unique_id "aoKaZyOpH4xzEfpQK76C3QAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-08-16 03:11:28
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.68.138.183
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.138.183
Observed=TCP dpt=80 in=enp0s6 ttl=57
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-16 01:22:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 21:21:55.052812 2026] [security2:error] [pid 3256840:tid 3256854] [client 172.68.138.183:14090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lamcohomecare.com"] [uri "/.git/config"] [unique_id "aoEQs8SjlLw8exJCVrvKkAAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 04:31:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.138.183 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 00:30:59.155971 2026] [security2:error] [pid 15897:tid 15897] [client 172.68.138.183:12114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.armstrongpartnersllc.com"] [uri "/.git/HEAD"] [unique_id "anqlg1Hwvl3m4_OjHtpXFQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-08 16:35:18
(1 month ago)
Web App Attack
Anonymous
2026-08-06 01:36:05
(1 month ago)
Attack detected: 172.68.138.183 [2026-08-06]
Categories: 21
--- webshell/admin probe (4 hits) ---
17 ...
show more
Attack detected: 172.68.138.183 [2026-08-06]
Categories: 21
--- webshell/admin probe (4 hits) ---
172.68.138.183 - - [28/May/2026:00:00:50 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.8225.1357 Safari/537.36"
172.68.138.183 - - [07/Jun/2026:03:25:25 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.9645.1969 Safari/537.36"
172.68.138.183 - - [12/Jun/2026:15:40:12 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.7595.1202 Safari/537.36"
172.68.138.183 - - [15/Jun/2026:03:39:11 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0
show less
Web App Attack
Anonymous
2026-07-22 00:45:26
(2 months ago)
Attack detected: 172.68.138.183 [2026-07-22]
Categories: 21
--- webshell/admin probe (4 hits) ---
17 ...
show more
Attack detected: 172.68.138.183 [2026-07-22]
Categories: 21
--- webshell/admin probe (4 hits) ---
172.68.138.183 - - [28/May/2026:00:00:50 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.8225.1357 Safari/537.36"
172.68.138.183 - - [07/Jun/2026:03:25:25 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.9645.1969 Safari/537.36"
172.68.138.183 - - [12/Jun/2026:15:40:12 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/56.0.7595.1202 Safari/537.36"
172.68.138.183 - - [15/Jun/2026:03:39:11 +0000] "GET /wp-content/uploads/2025/05/a6772069.gif HTTP/2.0" 304 645 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0
show less
Web App Attack