๐ซ๐ฎ
Erpelstolz
2026-06-11 14:00:56
(1 week ago)
external host: 172.68.195.185 - - [11/Jun/2026:16:00:53 +0200] "GET /wp-admin/install.php?step=1 HTT ...
show more
external host: 172.68.195.185 - - [11/Jun/2026:16:00:53 +0200] "GET /wp-admin/install.php?step=1 HTTP/1.1" 404 5663 "-" "http://erpelstolz.com/wp-admin/install.php?step=1" CF-Ray:a0a12505dadc5d65-FRA CF-IP:-
show less
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-10 01:42:00
(1 week ago)
172.68.195.185 - - [10/Jun/2026:
...
Brute-Force
๐ง๐ฌ
Stoyko Stoykov
2026-06-07 23:01:22
(1 week ago)
172.68.195.185 - - [08/Jun/2026:02:01:22 +0300] "GET /.env.old HTTP/2.0" 404 134 "-" "Mozilla/5.0 (W ...
show more
172.68.195.185 - - [08/Jun/2026:02:01:22 +0300] "GET /.env.old HTTP/2.0" 404 134 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 17:01:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 13:01:00.871294 2026] [security2:error] [pid 32285:tid 32285] [client 172.68.195.185:13151] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havelocktruckandauto.ca"] [uri "/.git/config"] [unique_id "aiGvTO8L2xjF2LoAbRJMJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 15:57:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 11:56:59.405343 2026] [security2:error] [pid 25682:tid 25682] [client 172.68.195.185:10661] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "renegadestudios.com"] [uri "/.git/config"] [unique_id "ah79S3jizncbuXfyi6tAegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:59:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:59:00.141656 2026] [security2:error] [pid 28554:tid 28554] [client 172.68.195.185:9411] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brexitop.com"] [uri "/.git/config"] [unique_id "ah6pZLbuIHIASx4UkjRttQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-13 04:07:17
(1 month ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐ฉ๐ช
acadeova
2026-04-10 12:42:58
(2 months ago)
๐จ Recon detected (nft drop)
SRC=172.68.195.185
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(jour ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.195.185
Observed=TCP dpt=80 in=enp0s6 ttl=59
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐บ๐ธ
mnsf
2026-04-04 23:05:31
(2 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 05:54:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 01:54:41.024740 2026] [security2:error] [pid 10053:tid 10053] [client 172.68.195.185:10447] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "networkzone.org.convoyforkids.com"] [uri "/.git/logs/HEAD"] [unique_id "adCnoe6-J5qSw5I4XhPBNgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 20:29:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.195.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 16:29:24.205026 2026] [security2:error] [pid 4580:tid 4607] [client 172.68.195.185:9796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "soonervolunteer.com"] [uri "/.env.bak"] [unique_id "adAjJHnnPDf4ZvDQlXf6wQAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-03 10:07:10
(2 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
Allolatr
2026-04-01 17:55:01
(2 months ago)
Apr 1 19:55:00 [redacted] j443: ::ffff:172.68.195.185 [redacted].ip-37-187-123.eu "GET /.git/logs/HE ...
show more
Apr 1 19:55:00 [redacted] j443: ::ffff:172.68.195.185 [redacted].ip-37-187-123.eu "GET /.git/logs/HEAD HTTP/2.0" 400 0 "-" "-" Apr 1 19:55:00 [redacted] j443: ::ffff:172.68.195.185 [redacted].ip-37-187-123.eu "GET /.env.development HTTP/2.0" 400 0 "-" "-" Apr 1 19:55:00 [redacted] j443: ::ffff:172.68.195.185 [redacted].ip-37-187-123.eu "GET /.env.staging HTTP/2.0" 400 0 "-" "-"...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-04-01 12:05:34
(2 months ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-04-01 10:49:35
(2 months ago)
[01/Apr/2026:12:49:34.942499 +0200] acz4Plie3oe2UZ2Jeu8eoQAAAAc 172.68.195.185 59294 127.0.0.1 7081
...
show more
[01/Apr/2026:12:49:34.942499 +0200] acz4Plie3oe2UZ2Jeu8eoQAAAAc 172.68.195.185 59294 127.0.0.1 7081
[01/Apr/2026:12:49:34.947964 +0200] acz4PmUrE4ziNdRUdizLqwAAAAU 172.68.195.185 59326 127.0.0.1 7081
[01/Apr/2026:12:49:34.953612 +0200] acz4PgortgXso_8S4N8vEgAAAAM 172.68.195.185 59346 127.0.0.1 7081
...
show less
Web App Attack