πΊπΈ
TPI-Abuse
2026-09-04 15:18:44
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:18:37.102533 2026] [security2:error] [pid 21657:tid 21657] [client 172.68.213.68:13303] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tikehaubookings.com"] [uri "/.git/config"] [unique_id "aprhTQBcE2LUuPXAXT0hgwAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-04 09:17:19
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 11:15:48
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:15:43.152106 2026] [security2:error] [pid 12295:tid 12295] [client 172.68.213.68:10831] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "essentialee.com"] [uri "/.git/config"] [unique_id "apaz3_a07-A5KCfKikRnJwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 10:12:47
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:12:39.833305 2026] [security2:error] [pid 14287:tid 14287] [client 172.68.213.68:10033] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dwiller.com"] [uri "/.git/config"] [unique_id "apalF_JxaaH9zJfGeaAV_wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 08:56:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:56:25.834326 2026] [security2:error] [pid 18154:tid 18154] [client 172.68.213.68:11712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcwenger.com"] [uri "/.git/config"] [unique_id "apaTOVOq2ZZvWQLTyrLmgQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
abdubhai
2026-07-09 08:05:27
(1 month ago)
172.68.213.68 - - [09/Jul/2026:1
...
Brute-Force
π³π±
homeshowdomain.nl
2026-05-22 22:00:59
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-21.
show less
Web App Attack
SSH
Hacking
π©πͺ
acadeova
2026-05-05 18:25:19
(4 months ago)
π¨ Recon detected (nft drop)
SRC=172.68.213.68
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journ ...
show more
π¨ Recon detected (nft drop)
SRC=172.68.213.68
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
πΊπ¦
URAN Publishing Service
2025-09-11 11:31:53
(11 months ago)
172.68.213.68 - - [11/Sep/2025:14:31:52 +0300] "GET /wp-admin/ HTTP/1.1" 404 196 "-" "-"
172.68.213. ...
show more
172.68.213.68 - - [11/Sep/2025:14:31:52 +0300] "GET /wp-admin/ HTTP/1.1" 404 196 "-" "-"
172.68.213.68 - - [11/Sep/2025:14:31:52 +0300] "GET /wp-content/wp-conflg.php HTTP/1.1" 404 196 "-" "-"
...
show less
Web App Attack
Anonymous
2025-08-31 05:40:11
(1 year ago)
[Sun Aug 31 07:40:10.502786 2025] [authz_core:error] [pid 10761] [client 172.68.213.68:23222] AH0163 ...
show more
[Sun Aug 31 07:40:10.502786 2025] [authz_core:error] [pid 10761] [client 172.68.213.68:23222] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 31 07:40:10.560645 2025] [authz_core:error] [pid 10761] [client 172.68.213.68:23222] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Aug 31 07:40:10.618412 2025] [authz_core:error] [pid 10761] [client 172.68.213.68:23222] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2025-05-17 05:39:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.213.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 17 01:39:29.643072 2025] [security2:error] [pid 1506043:tid 1506043] [client 172.68.213.68:36684] [client 172.68.213.68] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.c2cservices.com"] [uri "/wordpress/.env"] [unique_id "aCghEb5v03qcqwYYOWo2qAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Study Bitcoin π€
2025-05-07 14:46:39
(1 year ago)
Port probe to tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
π¨π¦
yukon.ca
2025-03-23 23:13:22
(1 year ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
Anonymous
2025-02-10 01:48:35
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-12-22 00:36:20
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH