๐ท๐บ
DZBOT
2026-06-17 15:27:35
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 22:21:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 18:21:06.680540 2026] [security2:error] [pid 31634:tid 31634] [client 172.68.193.159:9453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.deannesamuelskids.com"] [uri "/.git/config"] [unique_id "aiSdUtki_yD-j-UM6JzvvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-02 11:05:26
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:46:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:46:51.461567 2026] [security2:error] [pid 315:tid 315] [client 172.68.193.159:11490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnatuttle.com"] [uri "/.git/config"] [unique_id "ah60m5pT65uGyHavIm6YrQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 08:02:40
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:02:35.056724 2026] [security2:error] [pid 19886:tid 19886] [client 172.68.193.159:10605] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cabanaconstructionandpaving.com"] [uri "/.git/config"] [unique_id "ah6OG78luloKrjve9_MdLwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-30 07:05:26
(2 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-29 22:04:46
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-28.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-28 09:23:14
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 05:23:09.535911 2026] [security2:error] [pid 20675:tid 20675] [client 172.68.193.159:11182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chooseyourowntrail.com.robertmcatee.com"] [uri "/.git/config"] [unique_id "ahgJffwIuIExjBcdmooctwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-21 14:31:44
(4 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-05-20 20:28:01
(4 weeks ago)
external host: 172.68.193.159 - - [20/May/2026:22:27:58 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 172.68.193.159 - - [20/May/2026:22:27:58 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 8913 "-" "http://erpelstolz.com/wp-admin/install.php?step=1"
show less
Web App Attack
๐บ๐ธ
WellSpring
2026-05-19 13:09:47
(4 weeks ago)
wordpress scan on 901.today/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
Bad Web Bot
Web App Attack
๐ฉ๐ช
Prepaid-Host.com
2026-05-10 16:22:16
(1 month ago)
Web Exploit detected | Events: 15 | First seen: 2026-05-10 16:22 UTC | Last seen: 2026-05-10 16:22 U ...
show more
Web Exploit detected | Events: 15 | First seen: 2026-05-10 16:22 UTC | Last seen: 2026-05-10 16:22 UTC | Sample: Web Exploit detected by fail2ban jail 'plesk-wordpress': 15 failed attempt(s) from 172.68.193.159
Web Exploit detected by fail2ban jail 'plesk-wordpress': 15 failed attempt(s) from 172.68.193.159
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 05:12:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 01:12:47.678667 2026] [security2:error] [pid 13711:tid 13711] [client 172.68.193.159:14167] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dynamic-therapy-mn.com"] [uri "/.git/config"] [unique_id "afLkzyoAdLpc_TOOr0KmRQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-23 12:47:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 08:47:48.157414 2026] [security2:error] [pid 22666:tid 22734] [client 172.68.193.159:10041] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "busybeerestaurant.com"] [uri "/.git/config"] [unique_id "aeoU9PyabWDGMGz8S1u0uAAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-04-14 08:08:44
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack