๐ง๐ท
maviei
2026-06-26 07:25:36
(5 hours ago)
2026-06-26T04:25:34.182723-03:00 srv1251771 kernel: [2225561.132060] [UFW BLOCK] IN=eth0 OUT= MAC=40 ...
show more
2026-06-26T04:25:34.182723-03:00 srv1251771 kernel: [2225561.132060] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.8 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=39973 DF PROTO=TCP SPT=9988 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-26T04:25:35.226330-03:00 srv1251771 kernel: [2225562.173584] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.8 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=39974 DF PROTO=TCP SPT=9988 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
2026-06-26T04:25:36.248493-03:00 srv1251771 kernel: [2225563.196805] [UFW BLOCK] IN=eth0 OUT= MAC=40:e8:d4:b8:29:bb:44:38:39:ff:ff:41:08:00 SRC=172.71.148.8 DST=72.61.36.27 LEN=60 TOS=0x00 PREC=0x00 TTL=53 ID=39975 DF PROTO=TCP SPT=9988 DPT=8443 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ท๐บ
DZBOT
2026-06-24 13:27:20
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
oncord
2026-06-06 18:09:30
(2 weeks ago)
Form spam
Web Spam
๐ฉ๐ช
Blexyel
2026-06-06 17:40:15
(2 weeks ago)
172.71.148.8 - - [06/Jun/2026:19:40:14 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "curl/8.4.0"
...
show more
172.71.148.8 - - [06/Jun/2026:19:40:14 +0200] "GET /.git/config HTTP/1.1" 200 2116 "-" "curl/8.4.0"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 16:08:35
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 12:08:29.948789 2026] [security2:error] [pid 597:tid 631] [client 172.71.148.8:9230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newyorkplasticsurgery.us"] [uri "/.git/config"] [unique_id "aiGi_UnH4qw_jSqQKG7FagAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 20:38:08
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 16:38:04.472852 2026] [security2:error] [pid 7304:tid 7304] [client 172.71.148.8:11864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightningbug.farm"] [uri "/.git/config"] [unique_id "aiCQrDPltGcY3NX41OFjXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-03 01:05:05
(3 weeks ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:20:21
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:20:16.917178 2026] [security2:error] [pid 26963:tid 26963] [client 172.71.148.8:11896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grupoporvenir.com"] [uri "/.git/config"] [unique_id "ah7KgNqXG-5UMwTda8nwDAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-05-31 08:19:47
(3 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 12:43:27
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 08:43:22.453077 2026] [security2:error] [pid 13150:tid 13150] [client 172.71.148.8:13771] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carepage.pro.openkiwiai.com"] [uri "/.git/config"] [unique_id "ahg4ahNU3vfWpadi9DPXEQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-24 04:51:25
(1 month ago)
Aggressive web scan
Web App Attack
๐จ๐ญ
backslash
2026-05-15 06:48:03
(1 month ago)
block ruleset bad bot: misc bad content F608233CC4C86EE814CE8DDDA9C4A0D3C79882F6
Bad Web Bot
Anonymous
2026-05-12 03:06:00
(1 month ago)
[Tue May 12 05:05:58.620582 2026] [authz_core:error] [pid 26618] [client 172.71.148.8:13268] AH01630 ...
show more
[Tue May 12 05:05:58.620582 2026] [authz_core:error] [pid 26618] [client 172.71.148.8:13268] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue May 12 05:05:58.755157 2026] [authz_core:error] [pid 26618] [client 172.71.148.8:13268] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue May 12 05:05:58.887908 2026] [authz_core:error] [pid 26618] [client 172.71.148.8:13268] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 12:55:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 08:55:42.049418 2026] [security2:error] [pid 28684:tid 28684] [client 172.71.148.8:13828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elmosgrill.com.danged.com"] [uri "/.env"] [unique_id "af3dTkv94BCkXvWpb8n7JwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 11:18:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.148.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 07:18:04.398261 2026] [security2:error] [pid 29417:tid 29417] [client 172.71.148.8:11205] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdhlgroup.com"] [uri "/.git/config"] [unique_id "af3GbNzWAoNBqeS_HP7IYQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack