Anonymous
2026-09-30 23:15:31
(1 day ago)
172.68.164.67 - - [30/Sep/2026:20:15:30 -0300] "GET /.git/config HTTP/1.1" 403 874 "-" "Mozilla/5.0 ...
show more
172.68.164.67 - - [30/Sep/2026:20:15:30 -0300] "GET /.git/config HTTP/1.1" 403 874 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐ณ๐ฑ
BlueWire Hosting
2026-09-30 08:51:26
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฎ๐ฉ
Diskominfo Lumajang
2026-09-22 19:45:05
(1 week ago)
Security Event Detected by SOC Diskominfo Lumajang: event=alert, hits=16
Brute-Force
๐ช๐ธ
robotstxt
2026-09-22 02:55:41
(1 week ago)
172.68.164.67 - - [22/Sep/2026:02:55:02 +0000] "GET /wp-admin/js/ HTTP/2.0" 403 34104 "http://blimbu ...
show more
172.68.164.67 - - [22/Sep/2026:02:55:02 +0000] "GET /wp-admin/js/ HTTP/2.0" 403 34104 "http://blimburnseeds.de/wp-admin/js/" "Go-http-client/2.0" "140.245.116.147" edge="172.68.164.67"
172.68.164.67 - - [22/Sep/2026:02:55:03 +0000] "GET /wp-admin/css/colors/modern/ HTTP/2.0" 403 34104 "http://blimburnseeds.de/wp-admin/css/colors/modern/" "Go-http-client/2.0" "140.245.116.147" edge="172.68.164.67"
172.68.164.67 - - [22/Sep/2026:02:55:19 +0000] "GET /wp-includes/blocks/archives/ HTTP/2.0" 403 34106 "http://blimburnseeds.de/wp-includes/blocks/archives/" "Go-http-client/2.0" "140.245.116.147" edge="172.68.164.67"
172.68.164.67 - - [22/Sep/2026:02:55:20 +0000] "GET /wp-includes/blocks/code/ HTTP/2.0" 403 34104 "http://blimburnseeds.de/wp-includes/blocks/code/" "Go-http-client/2.0" "140.245.116.147" edge="172.68.164.67"
172.68.164.67 - - [22/Sep/2026:02:55:21 +0000] "GET /wp-content/uploads/ HTTP/2.0" 403 34106 "http://blimburnseeds.de/wp-content/uploads/" "Go-http-client/2.0" "140.245.116.1
...
show less
Web App Attack
๐ฉ๐ช
Hary74656
2026-09-21 06:28:38
(1 week ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
172.68.164.67 [21/Sep/2026:08:28:3 ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
172.68.164.67 [21/Sep/2026:08:28:38 +0200] [vhost hvm.hostmi.at] 403 "GET /.aws/credentials HTTP/2.0"
show less
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-18 14:49:22
(1 week ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-17 08:54:49
(2 weeks ago)
172.68.164.67 - - [17/Sep/2026:04:54:48 -0400] "GET /.aws/credentials HTTP/1.1" 403 6279 "-" "Mozill ...
show more
172.68.164.67 - - [17/Sep/2026:04:54:48 -0400] "GET /.aws/credentials HTTP/1.1" 403 6279 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-09 07:16:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:16:13.839319 2026] [security2:error] [pid 10550:tid 10550] [client 172.68.164.67:12046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "merlinaerospace.com"] [uri "/.env.sample"] [unique_id "aqEHvTD4YdUiSGJzUVaJggAAAA4"], referer: https://www.google.com/search?q=merlinaerospace.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-09-08 18:00:09
(3 weeks ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐จ๐ญ
4server
2026-09-08 15:48:19
(3 weeks ago)
[TueSep0817:48:15.4645922026][security2:error][pid2212852:tid2213121][client172.68.164.67:0]ModSecur ...
show more
[TueSep0817:48:15.4645922026][security2:error][pid2212852:tid2213121][client172.68.164.67:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\\\\\\\\.vscode/\"atREQUEST_FILENAME.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"1189\"][id\"350593\"][rev\"1\"][msg\"Atomicorp.comWAFRules:AttackBlocked-Dataleakage-attempttoaccessstoredvscodepasswords\"][severity\"CRITICAL\"][hostname\"lemox.ch\"][uri\"/.vscode/settings.json\"][unique_id\"aqAuP--yE4q-NmiPWYWt3QAAANg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 18:31:32
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:31:23.132301 2026] [security2:error] [pid 13610:tid 13702] [client 172.68.164.67:12283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.batonrougegazette.com.aafm.us"] [uri "/.env.dist"] [unique_id "apm8-zQw0ZchTMYjczkKNAAAAkU"], referer: https://www.google.com/search?q=www.batonrougegazette.com.aafm.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
eyesilyurt
2026-08-21 05:38:20
(1 month ago)
p- login authenticator failed Incorrect authentication data
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-18 02:00:14
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 22:00:05.100825 2026] [security2:error] [pid 2142:tid 2142] [client 172.68.164.67:14057] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.yoshiyukiya.com"] [uri "/.git/config"] [unique_id "aoO8pTrko1rhA9w7QetDCgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 23:56:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:55:54.917264 2026] [security2:error] [pid 21294:tid 21294] [client 172.68.164.67:9302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.trigonom.com"] [uri "/.git/config"] [unique_id "aoOfikD1fpls8vdsBV3uYwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 08:42:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.164.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:42:45.772065 2026] [security2:error] [pid 3160:tid 3160] [client 172.68.164.67:9520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "multilize.com"] [uri "/.git/HEAD"] [unique_id "aoLJhbt9T5FhYaw4EgySlwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack