๐ง๐ช
madeit
2026-08-27 11:21:06
(23 hours ago)
Web App Attack
Anonymous
2026-08-21 04:59:56
(1 week ago)
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /upload.php HTTP/2.0" 404 3577 "-" "Mozilla/5.0 ...
show more
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /upload.php HTTP/2.0" 404 3577 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "20.119.58.187"
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /wp-content/155.php HTTP/2.0" 404 3582 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "20.119.58.187"
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /wp-update.php HTTP/2.0" 404 3581 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "20.119.58.187"
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /about/function.php HTTP/2.0" 404 3582 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" "20.119.58.187"
172.68.245.82 - - [21/Aug/2026:04:59:54 +0000] "GET /asw.php HTTP/2.0" 404 3578 "-" "Mozilla/5.0 (Windows NT 10.0
...
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-17 14:19:35
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 10:19:28.551125 2026] [security2:error] [pid 11669:tid 11669] [client 172.68.245.82:13005] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skipandcarol.garretthillary.com"] [uri "/.git/HEAD"] [unique_id "aoMYcNPOdRpqDriNao6vDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 11:45:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 07:45:03.197219 2026] [security2:error] [pid 30359:tid 30373] [client 172.68.245.82:12651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.barnett-ranch.com"] [uri "/.git/config"] [unique_id "aoGiv4PMIOOcAett23IkPQAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 03:28:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 23:28:17.171735 2026] [security2:error] [pid 7563:tid 7563] [client 172.68.245.82:10200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thrudheim.org"] [uri "/.git/config"] [unique_id "aoEuUbpllEfJp8NBt1o2vgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-15 19:29:30
(1 week ago)
172.68.245.82 - - [15/Aug/2026:19:29:28 +0000] "GET /555.php HTTP/2.0" 404 3576 "-" "-" "20.65.105.2 ...
show more
172.68.245.82 - - [15/Aug/2026:19:29:28 +0000] "GET /555.php HTTP/2.0" 404 3576 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:28 +0000] "GET /bolt.php HTTP/2.0" 404 3576 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:28 +0000] "GET /he.php HTTP/2.0" 404 3575 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:28 +0000] "GET /doti.php HTTP/2.0" 404 3576 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:29 +0000] "GET /gmo.php HTTP/2.0" 404 3579 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:29 +0000] "GET /geck.php HTTP/2.0" 404 3581 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:29 +0000] "GET /file32.php HTTP/2.0" 404 3581 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:29 +0000] "GET /class9.php HTTP/2.0" 404 3581 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:30 +0000] "GET /file4.php HTTP/2.0" 404 3580 "-" "-" "20.65.105.233"
172.68.245.82 - - [15/Aug/2026:19:29:30 +0000] "GET /f
...
show less
Port Scan
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-13 11:20:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 07:20:10.721502 2026] [security2:error] [pid 2233661:tid 2233683] [client 172.68.245.82:9285] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lancasterdesignercraftsmen.org"] [uri "/.git/config"] [unique_id "an2oarxSmgqyoY9WfOHWMgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-13 10:36:45
(2 weeks ago)
[ThuAug1312:36:42.8186242026][security2:error][pid372193:tid372211][client172.68.245.82:0]ModSecurit ...
show more
[ThuAug1312:36:42.8186242026][security2:error][pid372193:tid372211][client172.68.245.82:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"casacarmen.ch\"][uri\"/.git/HEAD\"][unique_id\"an2eOqhL1ccQiXW4C3TNrQAAAQ8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฆ๐บ
oncord
2026-05-17 09:25:16
(3 months ago)
Form spam
Web Spam
๐บ๐ธ
TPI-Abuse
2026-05-15 09:23:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.245.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:23:35.529245 2026] [security2:error] [pid 31682:tid 31682] [client 172.68.245.82:11086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "files.nautos-usa.com"] [uri "/.env.vercel"] [unique_id "agbmF46icPVDa9xk9_7RGgAAAAk"], referer: https://www.google.com/search?q=files.nautos-usa.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:06:25
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-13.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-04-25 03:55:39
(4 months ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฆ๐บ
oncord
2026-04-17 01:21:12
(4 months ago)
Form spam
Web Spam
๐บ๐ธ
mnsf
2026-04-08 01:05:40
(4 months ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-04-06 18:06:07
(4 months ago)
Scanning/Probing (15)
Brute-Force
Web App Attack