π©πͺ
LavrinenkoRM
2026-10-02 02:11:51
(2 days ago)
Sentinel WAF: web/rozfarbui.org.ua; Honeypot URL; confidence=90; blocked_at=2026-10-02T01:58:55.2061 ...
show more
Sentinel WAF: web/rozfarbui.org.ua; Honeypot URL; confidence=90; blocked_at=2026-10-02T01:58:55.206175+00:00
show less
Web App Attack
π§π¬
Stoyko Stoykov
2026-10-01 05:51:34
(3 days ago)
172.71.119.65 - - [01/Oct/2026:08:51:33 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5 ...
show more
172.71.119.65 - - [01/Oct/2026:08:51:33 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
π§π¬
Stoyko Stoykov
2026-09-30 01:40:09
(4 days ago)
172.71.119.65 - - [30/Sep/2026:04:40:07 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5 ...
show more
172.71.119.65 - - [30/Sep/2026:04:40:07 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
π§π¬
Stoyko Stoykov
2026-09-27 06:26:50
(1 week ago)
172.71.119.65 - - [27/Sep/2026:09:26:49 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5 ...
show more
172.71.119.65 - - [27/Sep/2026:09:26:49 +0300] "GET /config/config.js HTTP/2.0" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 01:11:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 21:11:06.149123 2026] [security2:error] [pid 29095:tid 29095] [client 172.71.119.65:10714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "orcastrong.com"] [uri "/.git/config"] [unique_id "arcbqtyc2tOHKTOHivjajgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
openstrike.co.uk
2026-09-21 05:14:34
(1 week ago)
16 attacks on Wordpress URLs, PHP URLs:
GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET /xmlrpc.p ...
show more
16 attacks on Wordpress URLs, PHP URLs:
GET /sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET /xmlrpc.php?rsd HTTP/1.1
show less
Web App Attack
π«π·
dynamix
2026-09-20 13:04:03
(1 week ago)
Multiple WAF Violations
Web App Attack
π«π·
dynamix
2026-09-12 18:33:02
(3 weeks ago)
Multiple WAF Violations
Web App Attack
π§πͺ
madeit
2026-09-06 09:04:17
(4 weeks ago)
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-01 21:07:02
(1 month ago)
[Wed Sep 02 07:07:00.670638 2026] [security2:error] [pid 305200] [client 172.71.119.65:12800] [clien ...
show more
[Wed Sep 02 07:07:00.670638 2026] [security2:error] [pid 305200] [client 172.71.119.65:12800] [client 172.71.119.65] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/HEAD"] [unique_id "apc-dLMTDCtfCYkj4vQXdgAAAAs"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:58:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:57:56.746717 2026] [security2:error] [pid 27685:tid 27685] [client 172.71.119.65:12688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swetzer.net"] [uri "/.git/config"] [unique_id "apZbVD1KfkoymTo2EtcbugAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 20:28:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 16:28:35.184885 2026] [security2:error] [pid 1002:tid 1002] [client 172.71.119.65:13323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuerec.com"] [uri "/.git/config"] [unique_id "apXj86OZ4GkyfRFBWsWPpAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 03:57:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:57:48.696415 2026] [security2:error] [pid 4927:tid 4927] [client 172.71.119.65:11799] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hdestimating.com"] [uri "/.git/config"] [unique_id "apT7vECSnUp8K6y-BsasFQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
kivitendo.de
2026-08-31 03:42:03
(1 month ago)
[Mon Aug 31 05:42:02.537147 2026] [access_compat:error] [pid 15809:tid 15816] [client 172.71.119.65: ...
show more
[Mon Aug 31 05:42:02.537147 2026] [access_compat:error] [pid 15809:tid 15816] [client 172.71.119.65:13422] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/config
[Mon Aug 31 05:42:02.537935 2026] [access_compat:error] [pid 15808:tid 15845] [client 172.71.119.65:13417] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/HEAD
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 22:45:29
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.119.65 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:45:25.942660 2026] [security2:error] [pid 21918:tid 21918] [client 172.71.119.65:13884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.chrismoratz.com"] [uri "/.git/config"] [unique_id "apIPhdmRf2zatub24o3YQgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack