๐บ๐ธ
mawan
2026-07-26 23:17:26
(18 hours ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-24 10:10:23
(3 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 07:43:30
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mawan
2026-07-19 04:52:23
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
mawan
2026-07-17 20:05:59
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
acadeova
2026-06-23 18:56:44
(1 month ago)
๐จ Recon detected (nft drop)
SRC=172.68.50.162
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journ ...
show more
๐จ Recon detected (nft drop)
SRC=172.68.50.162
Observed=TCP dpt=80 in=enp0s6 ttl=58
Time=recent(journalctl: 10 minutes ago)
Assessment=Generic scanning / reconnaissance (PORT_SCAN)
show less
Port Scan
๐ท๐ด
ReporTR
2026-02-06 21:15:42
(5 months ago)
Repeated malicious activity detected by Fail2Ban jail 'plesk-apache'. TCP connection completed. IP b ...
show more
Repeated malicious activity detected by Fail2Ban jail 'plesk-apache'. TCP connection completed. IP banned.
show less
Hacking
Web App Attack
๐ณ๐ฑ
ReporTR
2026-01-27 16:51:49
(6 months ago)
Repeated malicious activity detected by Fail2Ban jail 'plesk-modsecurity'. TCP connection completed. ...
show more
Repeated malicious activity detected by Fail2Ban jail 'plesk-modsecurity'. TCP connection completed. IP banned.
show less
Hacking
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2025-04-13 13:42:41
(1 year ago)
2 port probes: 2x tcp/80 (http)
[srv125]
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 04:54:49
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 00:54:46.037140 2025] [security2:error] [pid 7755:tid 7755] [client 172.68.50.162:29286] [client 172.68.50.162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.top-brand.us"] [uri "/api/.env"] [unique_id "Z9erFkMjp4JRSQ5RsQASWAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-16 07:14:05
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 16 03:13:56.236207 2025] [security2:error] [pid 1209418:tid 1209418] [client 172.68.50.162:56044] [client 172.68.50.162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/dev/.env"] [unique_id "Z9Z6NL5wLueUERDpVHnphgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Study Bitcoin ๐ค
2024-11-29 18:24:38
(1 year ago)
Port probe to tcp/443 (https)
[srv130]
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-11-10 13:51:27
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
thefoofighter
2024-10-26 07:47:48
(1 year ago)
[Sat Oct 26 07:47:47.877723 2024] [:error] [pid 3160669] [client 172.68.50.162:10130] [client 172.68 ...
show more
[Sat Oct 26 07:47:47.877723 2024] [:error] [pid 3160669] [client 172.68.50.162:10130] [client 172.68.50.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.2"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cathalmcnally.com"] [uri "/app/.env"] [unique_id "Zxyeo4FnTmO4TKQ3BZMe3gAAAAM"]
[Sat Oct 26 07:47:48.432168 2024] [:error] [pid 3160669] [client 172.68.50.162:10130] [client 172.68.50.162] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "93"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-25 09:48:51
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.68.50.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 25 05:48:46.406330 2024] [security2:error] [pid 1238:tid 1238] [client 172.68.50.162:9542] [client 172.68.50.162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ard.global"] [uri "/apps/.env"] [unique_id "Zxtpfpletq9mvo--wL8LHAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack