π©πͺ
4server
2026-08-24 16:39:34
(33 minutes ago)
[MonAug2418:39:32.3209602026][security2:error][pid1288193:tid1288309][client172.69.222.90:0]ModSecur ...
show more
[MonAug2418:39:32.3209602026][security2:error][pid1288193:tid1288309][client172.69.222.90:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aaaa6877.org\"][uri\"/.git/config\"][unique_id\"aoxzxJksjB-wE1Z_MBXCrQAAAkc\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 13:39:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:38:53.376176 2026] [security2:error] [pid 21558:tid 21558] [client 172.69.222.90:10600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cnbruselas.com"] [uri "/.git/HEAD"] [unique_id "aoxJbe5OLQfutOo8neHylQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
S.O.B.A. Dev.
2026-08-23 09:40:19
(1 day ago)
Persistent port scanning or vulnerability scanning
Port Scan
πΊπΈ
TPI-Abuse
2026-08-22 17:13:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:13:48.728789 2026] [security2:error] [pid 20495:tid 20495] [client 172.69.222.90:11282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.bipocmentalhealthcoalition.org"] [uri "/.git/config"] [unique_id "aonYzC2dx-wY3L0NKKLOTQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
madeit
2026-08-22 16:47:07
(2 days ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 23:25:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:25:50.639396 2026] [security2:error] [pid 11914:tid 11914] [client 172.69.222.90:13975] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.centrosteckerl.com"] [uri "/.git/HEAD"] [unique_id "aoTp_iIEWSmuTlNyCaBfaAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 10:54:26
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:54:19.481603 2026] [security2:error] [pid 17617:tid 17617] [client 172.69.222.90:10373] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fullyevil.com"] [uri "/.git/config"] [unique_id "aoQ52wfFJrNxJN8Y8jp-9wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
OptimusGO
2026-08-10 16:08:20
(2 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-10 17:08:20 UTC
Log evidence:
172.69.222.90 - - [10/Aug/2026:17:08:18 +0100] "GET /secrets/index%2ejs HTTP/1.1" 404 118 "-" "curl/8.7.1"
08/10/2026-17:08:18.605747 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.69.222.90:10432 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
π§πͺ
madeit
2026-08-09 12:47:01
(2 weeks ago)
Web App Attack
Anonymous
2026-07-29 23:55:08
(3 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-15 02:06:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.69.222.90 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 22:06:25.052880 2026] [security2:error] [pid 23060:tid 23071] [client 172.69.222.90:9971] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beltagin.com"] [uri "/.git/config"] [unique_id "albrIYzk7Q7h86jj230E3gAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
OptimusGO
2026-06-27 23:39:29
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-06-28 00:39:29 UTC
Log evidence:
172.69.222.90 - - [28/Jun/2026:00:39:28 +0100] "GET /assets/js/aws-config.js HTTP/1.1" 404 118 "-" "curl/8.7.1"
06/28/2026-00:39:28.845648 [**] [1:1000201:1] SCANNER: Bot-like User-Agent Detected [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 172.69.222.90:13649 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
πΊπΈ
mnsf
2026-06-16 03:06:06
(2 months ago)
Abuse Detected (1)
Brute-Force
Web App Attack
π§πΎ
lns.bz
2026-05-08 15:34:54
(3 months ago)
Too many 404 requests [BY]
Web App Attack
π§πΎ
lns.bz
2026-04-13 17:24:23
(4 months ago)
.env scanning [BY]
Web App Attack