๐ฉ๐ช
acadeova
2026-06-10 19:24:33
(1 hour ago)
๐จ Recon detected (nft drop)
SRC=172.68.194.201
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.194.201
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-06-10 04:09:47
(16 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-07 02:42:57
(3 days ago)
172.68.194.201 - - [07/Jun/2026:04:42:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
172.68.194.201 - - [07/Jun/2026:04:42:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/127.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 15:26:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 11:25:59.679228 2026] [security2:error] [pid 20452:tid 20452] [client 172.68.194.201:14078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "download.nsfwmanager.com"] [uri "/.git/config"] [unique_id "aiLqh68asc_EUHP3vtbG9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 13:33:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 09:32:54.332815 2026] [security2:error] [pid 1990:tid 1990] [client 172.68.194.201:11038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radar24hrs.com"] [uri "/.git/config"] [unique_id "aiLQBsQQRoALv9MWIP7qDQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 01:30:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 21:30:06.416398 2026] [security2:error] [pid 23459:tid 23459] [client 172.68.194.201:12834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taafe.xyz"] [uri "/.git/config"] [unique_id "aiDVHq38a7HbUBCqalZuEAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-01 15:30:57
(1 week ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 15:30:36โ15:30:37 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php, /wp-admin/install.php?step=1
UA: "http://zvxlabs.com/wp-admin/install.php?step=1"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
acadeova
2026-06-01 02:01:37
(1 week ago)
๐จ Recon detected (nft drop)
SRC=172.68.194.201
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.194.201
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ท๐บ
DZBOT
2026-05-21 06:05:15
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
2048
2026-04-07 02:36:28
(2 months ago)
2026-04-07T03:36:25.421873+01:00 machodeer kernel: [3786205.045018] [UFW BLOCK] IN=ens3 OUT= MAC=RED ...
show more
2026-04-07T03:36:25.421873+01:00 machodeer kernel: [3786205.045018] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.68.194.201 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=481 DF PROTO=TCP SPT=12792 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-04-07T03:36:26.473793+01:00 machodeer kernel: [3786206.098952] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.68.194.201 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=482 DF PROTO=TCP SPT=12792 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-04-07T03:36:27.496846+01:00 machodeer kernel: [3786207.121948] [UFW BLOCK] IN=ens3 OUT= MAC=REDACTED SRC=172.68.194.201 DST=REDACTED LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=483 DF PROTO=TCP SPT=12792 DPT=443 WINDOW=65535 RES=0x00 SYN URGP=0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-06 08:30:37
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 04:30:28.739967 2026] [security2:error] [pid 4717:tid 4717] [client 172.68.194.201:11406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noviasaltovacio.com.mx.spyasociados.com"] [uri "/.git/refs/heads/master"] [unique_id "adNvJBpjY-CtC7H68CawDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-05 08:38:26
(2 months ago)
172.68.194.201 - - [05/Apr/2026:11:38:19 +0300] "GET /core/.env HTTP/1.1" 404 766 "-" "-"
172.68.194 ...
show more
172.68.194.201 - - [05/Apr/2026:11:38:19 +0300] "GET /core/.env HTTP/1.1" 404 766 "-" "-"
172.68.194.201 - - [05/Apr/2026:11:38:26 +0300] "GET /site/.env HTTP/1.1" 404 766 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 21:13:11
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 17:13:01.363196 2026] [security2:error] [pid 32366:tid 32366] [client 172.68.194.201:13563] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bjfrancislaw.com"] [uri "/.git/config"] [unique_id "adF-3Sd5yHsigwirZgc9vwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 01:35:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.194.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 21:35:07.124321 2026] [security2:error] [pid 19698:tid 19698] [client 172.68.194.201:13318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.tcomputerguy.com"] [uri "/.env.production"] [unique_id "adBqywhCwHmA8gCUbhjDqQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-03 07:00:01
(2 months ago)
Multiple WAF Violations
Web App Attack