πΊπΈ
xxkodedxx
2026-07-20 22:10:07
(1 month ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
Active: 22:09:09β22:09:10 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php, /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-07-20 09:31:38
(1 month ago)
Persistent port scanning or vulnerability scanning
Port Scan
π©πͺ
Blexyel
2026-07-06 18:42:02
(2 months ago)
172.68.193.190 - - [06/Jul/2026:20:42:02 +0200] "GET /.git/info/exclude HTTP/1.1" 200 240 "-" "Mozil ...
show more
172.68.193.190 - - [06/Jul/2026:20:42:02 +0200] "GET /.git/info/exclude HTTP/1.1" 200 240 "-" "Mozilla/5.0 (Windows NT 10.0; rv:78.0) Gecko/20100101 Firefox/78.0" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-06-17 00:07:17
(3 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 06:48:51
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 02:48:33.186589 2026] [security2:error] [pid 18212:tid 18212] [client 172.68.193.190:10288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texassportsmansassociation.org.cajunfriedturkey.com"] [uri "/.env.dev"] [unique_id "aiz9QeOHRasaYwhpltvPkgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²π½
octageeks.com
2026-06-11 04:07:17
(3 months ago)
Wordpress malicious attack:[octawp]
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-03 07:12:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 03:12:31.457452 2026] [security2:error] [pid 3716:tid 3738] [client 172.68.193.190:10306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chelseyrae.com"] [uri "/.git/config"] [unique_id "afb1XwXhVmAtB775Xm2DOgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-30 04:58:34
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 00:58:30.715607 2026] [security2:error] [pid 2214:tid 2214] [client 172.68.193.190:14283] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drmaterna.com"] [uri "/.git/config"] [unique_id "afLhdrQapHfaahanil2QkgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-14 03:15:54
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 23:15:48.327291 2026] [security2:error] [pid 1349177:tid 1349177] [client 172.68.193.190:10744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.paavoharkonen.com"] [uri "/.git/config"] [unique_id "ad2xZGdTHErcvkapyK0kjAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-07 03:10:20
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 23:10:15.138968 2026] [security2:error] [pid 1373607:tid 1373607] [client 172.68.193.190:9378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.duhcathlon.com"] [uri "/.git/logs/HEAD"] [unique_id "adR1l5euAUWS_5UTJZSiggAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-05 07:30:25
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 03:30:20.337947 2026] [security2:error] [pid 15963:tid 15963] [client 172.68.193.190:13742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danafrostick.com"] [uri "/.env.test"] [unique_id "adIPjAZUpl08KjfwPFO6PAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-04-04 14:18:04
(5 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 12:58:46
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 08:58:41.163253 2026] [security2:error] [pid 18785:tid 18785] [client 172.68.193.190:11840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.desertrosedoves.com"] [uri "/.git/refs/heads/master"] [unique_id "adELAWB1tGPGkCSmNyRMmgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-04-04 03:24:54
(5 months ago)
Restricted File Access Attempt. Matched phrase "/.git/" at REQUEST_FILENAME. (930130-122)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 00:44:32
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.193.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 20:44:25.654326 2026] [security2:error] [pid 3608:tid 3608] [client 172.68.193.190:11778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.usaerosp.aluthienproperties.com"] [uri "/.env.development"] [unique_id "adBe6ViET5bMq8VFFkOhuAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack