๐บ๐ธ
mawan
2026-08-21 23:46:30
(2 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 01:52:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 21:52:47.921280 2026] [security2:error] [pid 13385:tid 13385] [client 172.69.166.21:9924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ceezees.com"] [uri "/.git/HEAD"] [unique_id "aoO679a41hH5q0cNUQ8jPwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:53:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:53:26.447966 2026] [security2:error] [pid 16186:tid 16186] [client 172.69.166.21:12525] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.emmlogistics.com"] [uri "/.git/HEAD"] [unique_id "aoFsdnFoTn11ZK3vzzpHiAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 07:26:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:26:23.861988 2026] [security2:error] [pid 16224:tid 16224] [client 172.69.166.21:10269] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.804websolutions.com"] [uri "/.git/config"] [unique_id "aoFmH3HyirVxbGlpMK1SgAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-12 10:03:34
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 09:05:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 05:05:24.176964 2026] [security2:error] [pid 3885:tid 3910] [client 172.69.166.21:11764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bobchaos.com"] [uri "/.git/HEAD"] [unique_id "anrl1C4mZPcgwA_fm4lL1QAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 03:46:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.166.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 23:46:23.331103 2026] [security2:error] [pid 3810530:tid 3810560] [client 172.69.166.21:9878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.isa-energy.net"] [uri "/.git/HEAD"] [unique_id "anqbD0KdvPkXRKUx8MdFXwAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 13:30:26
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-06-30 07:53:56
(1 month ago)
172.69.166.21 - - > tecnicman.it [30/Jun/2026:09:53:49 +0200] "POST /wp-login.php HTTP/2.0" 301 162 ...
show more
172.69.166.21 - - > tecnicman.it [30/Jun/2026:09:53:49 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:89.0) Gecko/20100101 Firefox/89.0.2" "168.138.188.55"
172.69.166.21 - - > tecnicman.it [30/Jun/2026:09:53:55 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "168.138.188.55"
172.69.166.21 - - > tecnicman.it [30/Jun/2026:09:53:55 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "168.138.188.55"
172.69.166.21 - - > tecnicman.it [30/Jun/2026:09:53:56 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:90.0) Gecko/20100101 Firefox/90.0.1" "168.138.188.55"
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-06-27 09:51:16
(1 month ago)
172.69.166.21 - - > tecnicman.it [27/Jun/2026:11:51:12 +0200] "POST /wp-login.php HTTP/2.0" 301 162 ...
show more
172.69.166.21 - - > tecnicman.it [27/Jun/2026:11:51:12 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36" "161.118.221.77"
172.69.166.21 - - > tecnicman.it [27/Jun/2026:11:51:13 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36" "161.118.221.77"
172.69.166.21 - - > tecnicman.it [27/Jun/2026:11:51:14 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/93.0.4577.63 Safari/537.36" "161.118.221.77"
172.69.166.21 - - > tecnicman.it [27/Jun/2026:11:51:15 +0200] "POST /wp-login.php HTTP/2.0" 301 162 "https://tecnicman.it/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:91.0) Gecko/20100101 Firefox/91
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
wimaxnz
2026-05-15 02:12:27
(3 months ago)
Automated report from 247 Guardian: repeated malicious activity detected. | reason=nginx_badpath
Brute-Force
SSH
Port Scan
๐ณ๐ฑ
homeshowdomain.nl
2026-05-10 21:59:58
(3 months ago)
Auto-ban: >3000 req/min op 2026-05-10
Web App Attack
SSH
Hacking
๐บ๐ธ
2k11.co.za
2026-03-19 00:53:29
(5 months ago)
172.69.166.21 - - [18/Mar/2026:20:53:16 -0400] "GET /wp-admin.php HTTP/1.1" 404 187 "-" "Mozilla/5.0 ...
show more
172.69.166.21 - - [18/Mar/2026:20:53:16 -0400] "GET /wp-admin.php HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.125 Safari/537.36"
172.69.166.21 - - [18/Mar/2026:20:53:28 -0400] "GET /cgi-bin/bypass.php HTTP/1.1" 404 187 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0.3945.88 Safari/537.36"
...
show less
Brute-Force
๐จ๐ณ
ThreatBook.io
2025-12-26 22:47:54
(7 months ago)
2025-12-26 06:36:25 /uploads/
Web App Attack
๐จ๐ณ
ThreatBook.io
2025-12-15 22:59:30
(8 months ago)
2025-12-15 01:24:57 /autoload_classmap/function.php
Web App Attack