๐ฉ๐ช
Lazentis
2026-06-21 02:47:34
(2 days ago)
Unauthorized access attempt to port 8080 (tcp)
Brute-Force
SSH
๐ณ๐ฟ
Tripwire
2026-05-31 21:37:02
(3 weeks ago)
Fake ChatGPT bot "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; + ...
show more
Fake ChatGPT bot "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
show less
Bad Web Bot
๐จ๐ญ
backslash
2026-05-24 10:06:07
(4 weeks ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-23 13:33:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 09:33:04.184062 2026] [security2:error] [pid 14865:tid 14865] [client 172.69.136.176:11418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "winwithbrad.com"] [uri "/.git/config"] [unique_id "ahGskDJYTgkwhQ53RE0omgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 09:03:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 05:03:05.489923 2026] [security2:error] [pid 24790:tid 24790] [client 172.69.136.176:10975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cedula3.com"] [uri "/.git/config"] [unique_id "ahFtSYZcwVJS4FSO7x9SwAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 08:42:24
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 04:42:16.063654 2026] [security2:error] [pid 28381:tid 28381] [client 172.69.136.176:10021] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "microdot.net"] [uri "/.git/config"] [unique_id "ahFoaPcP9Cal6QshrgwJFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-05-23 07:20:59
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-20 10:16:16
(1 month ago)
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:56:22 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:56:28 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:10:07:03 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:10:15:19 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:10:16:12 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-05-20 09:32:20
(1 month ago)
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:14:36 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:23:58 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:30:54 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:32:15 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [20/May/2026:09:32:18 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-19 15:50:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 11:50:51.348525 2026] [security2:error] [pid 26597:tid 26597] [client 172.69.136.176:12764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earscript.net"] [uri "/.env.dev"] [unique_id "agyG27iLjTwQmyHq_ylqqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 11:27:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 07:26:53.723865 2026] [security2:error] [pid 17776:tid 17776] [client 172.69.136.176:12531] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ceta-arts.com"] [uri "/.env.save"] [unique_id "agcC_ZokSIVVmu0uS24oUgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 10:14:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 06:13:59.022970 2026] [security2:error] [pid 22488:tid 22488] [client 172.69.136.176:11049] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charts.bccworldmedia.com"] [uri "/.env.dev"] [unique_id "agbx56lJfG9lI2BkWPSREAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 09:32:56
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.136.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 05:32:52.353045 2026] [security2:error] [pid 6443:tid 6443] [client 172.69.136.176:12580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cthog.xyz"] [uri "/.env.local"] [unique_id "agboRNtWvdlaUCa6-ZDqIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-14 08:04:32
(1 month ago)
[ThuMay1410:04:26.2452652026][security2:error][pid2770553:tid2770760][client172.69.136.176:0]ModSecu ...
show more
[ThuMay1410:04:26.2452652026][security2:error][pid2770553:tid2770760][client172.69.136.176:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"piffarerio.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"agWCCj2oB_hSIq0_gdb4VAAAAQA\"]
show less
Hacking
Web App Attack
Anonymous
2026-05-14 07:52:48
(1 month ago)
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: * ...
show more
(caddyscan) Scanner path probe from 172.69.136.176 (EE/Estonia/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.69.136.176 - - [14/May/2026:07:52:23 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [14/May/2026:07:52:26 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [14/May/2026:07:52:29 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [14/May/2026:07:52:36 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.69.136.176 - - [14/May/2026:07:52:45 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan