๐ง๐ช
madeit
2026-08-27 19:31:58
(6 days ago)
Web App Attack
๐ฉ๐ช
Ha1fdan
2026-08-20 04:38:43
(1 week ago)
{"level":"info","ts":1787200722.790825,"logger":"http.log.access","msg":"handled request","request": ...
show more
{"level":"info","ts":1787200722.790825,"logger":"http.log.access","msg":"handled request","request":{"remote_ip":"172.68.245.223","remote_port":"10764","client_ip":"172.68.245.223","proto":"HTTP/1.1","method":"GET","host":"hypixel.dk","uri":"/form3.php","headers":{"Cf-Ipcountry":["US"],"Cf-Visitor":["{\"scheme\":\"http\"}"],"Cf-Ray":["a2deb5c45bc8c94c-IAD"],"Cf-Connecting-Ip":["20.65.69.59"],"X-Forwarded-Proto":["http"],"Cdn-Loop":["cloudflare; loops=1"],"X-Forwarded-For":["20.65.69.59"],"Accept-Encoding":["gzip"],"Connection":["Keep-Alive"]}},"bytes_read":0,"user_id":"","duration":0.000084281,"size":0,"status":404,"resp_headers":{"Server":["Caddy"]}}
{"level":"info","ts":1787200722.9242516,"logger":"http.log.access","msg":"handled request","request":{"remote_ip":"172.68.245.223","remote_port":"10764","client_ip":"172.68.245.223","proto":"HTTP/1.1","method":"GET","host":"hypixel.dk","uri":"/wp-crom.php","headers":{"Cf-Ray":["a2deb5c5ee60c94c-IAD"],"Cf-Ipcountry":["US"],"Connection":["K
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 15:35:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 11:35:17.931594 2026] [security2:error] [pid 25393:tid 25403] [client 172.68.245.223:10873] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.rosicruciansociety.com"] [uri "/.git/config"] [unique_id "aoMqNdzjXHeBAG1R6HEiUgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 09:06:08
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:06:01.422000 2026] [security2:error] [pid 32553:tid 32553] [client 172.68.245.223:12561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forensicwater.waterarchitecture.com"] [uri "/.git/config"] [unique_id "aoLO-RHiOzRxCbwW3ihTlwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-17 02:43:08
(2 weeks ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-16 22:01:19
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-16 08:35:14
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:35:09.957353 2026] [security2:error] [pid 8270:tid 8270] [client 172.68.245.223:11886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.flashbackmusicmemories.com"] [uri "/.git/HEAD"] [unique_id "aoF2PUHIbjHZaBT8qtd_nQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 06:50:41
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 02:50:35.467418 2026] [security2:error] [pid 19294:tid 19294] [client 172.68.245.223:12268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lahamllc.com"] [uri "/.git/HEAD"] [unique_id "aoFdu3zuiyDgjxCRkhA2CAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-04-04 02:05:37
(4 months ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 11:57:08
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 07:57:02.270359 2026] [security2:error] [pid 18193:tid 18193] [client 172.68.245.223:9658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.grupogasa.com"] [uri "/.git/logs/HEAD"] [unique_id "acu2jtkN2occRdXytUzbDwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 05:33:03
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 01:32:58.513665 2026] [security2:error] [pid 7646:tid 7646] [client 172.68.245.223:11044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.razeemco.com"] [uri "/.env.test"] [unique_id "actciuEyp2_-n64iX4KfmwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 01:45:40
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 21:45:36.647607 2026] [security2:error] [pid 24488:tid 24488] [client 172.68.245.223:13851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wgld.cmabiblequizzing.org"] [uri "/docker/.env.local"] [unique_id "acsnQHY6TdJ9ZEsD9lhxRgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 00:01:17
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:01:09.307956 2026] [security2:error] [pid 27249:tid 27249] [client 172.68.245.223:12897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.vespaitaliancafe.com"] [uri "/.env.test"] [unique_id "acsOxZMO11KEDiedA2xo0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-03-30 20:08:25
(5 months ago)
Scanning/Probing (18)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 17:02:27
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 13:02:21.413235 2026] [security2:error] [pid 9030:tid 9030] [client 172.68.245.223:10456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.missyshinoski.info.joshuashands.org"] [uri "/.env"] [unique_id "acqsnVjGC4oc3UZVCIYgOgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack