๐ง๐ช
madeit
2026-09-22 17:37:12
(1 day ago)
Web App Attack
๐จ๐ฑ
ifiguero
2026-09-17 05:54:08
(6 days ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
๐ง๐ช
madeit
2026-09-13 23:54:55
(1 week ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-11 21:59:29
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-11
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-09-08 15:48:15
(2 weeks ago)
[TueSep0817:48:10.5447592026][security2:error][pid2212852:tid2213116][client172.71.152.71:0]ModSecur ...
show more
[TueSep0817:48:10.5447592026][security2:error][pid2212852:tid2213116][client172.71.152.71:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"lemox.ch\"][uri\"/.docker/config.json\"][unique_id\"aqAuOu-yE4q-NmiPWYWt2gAAANU\"]
show less
Hacking
Web App Attack
๐ฎ๐ฉ
bps-statistics
2026-09-07 18:07:09
(2 weeks ago)
Remote Shell Reconnaisance: "2026-09-08T01:07:09.992+07:00" "/mgmt/shared/iapp/rpm-spec-creator" "17 ...
show more
Remote Shell Reconnaisance: "2026-09-08T01:07:09.992+07:00" "/mgmt/shared/iapp/rpm-spec-creator" "172.71.152.71" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-17 09:40:28
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.152.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.152.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:40:25.749544 2026] [security2:error] [pid 30448:tid 30448] [client 172.71.152.71:9735] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thestardance.com"] [uri "/.git/config"] [unique_id "aoLXCXRamAh-gAtOdBCoAQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 22:37:05
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.152.71 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.152.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:36:59.716159 2026] [security2:error] [pid 23692:tid 23692] [client 172.71.152.71:12278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clossglobal.com"] [uri "/.git/config"] [unique_id "aoI7ixK2pTLIyHoE-pOmwwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-16 16:12:57
(1 month ago)
Web App Attack
๐ฉ๐ช
NewWavesApp
2025-12-30 17:06:11
(8 months ago)
(mod_security) mod_security triggered on hostname [redacted] 172.71.152.71 (SG/Singapore/-)
SQL Injection
๐ฎ๐ฉ
hermawan
2025-11-28 05:27:14
(9 months ago)
[Fri Nov 28 11:57:38.974765 2025] [security2:error] [pid 1444106:tid 139900415272640] [client 172.71 ...
show more
[Fri Nov 28 11:57:38.974765 2025] [security2:error] [pid 1444106:tid 139900415272640] [client 172.71.152.71:39941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "399"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2024/12_Desember_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Desember_2024-600.webp HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-malang.info"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2024/12_Desember_2024/Infografis_Bulanan_Curah_Hujan_Maksimum_Bulan_Desember_2024-600.webp"] [unique_id "aSkrwrExOsqx2RF-d0tXHQAAEhg"] [staklim-malang.info] [staklim-malang.info] top=
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-12 13:22:40
(10 months ago)
[Wed Nov 12 20:22:10.383413 2025] [security2:error] [pid 4418:tid 140633682421440] [client 172.71.15 ...
show more
[Wed Nov 12 20:22:10.383413 2025] [security2:error] [pid 4418:tid 140633682421440] [client 172.71.152.71:43921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg"] [unique_id "aRSKAuIg7_iALn4y-r-3DAADiRE"] [staklim-j
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-10 12:44:12
(10 months ago)
[Mon Nov 10 19:35:53.577999 2025] [security2:error] [pid 22249:tid 140246491576000] [client 172.71.1 ...
show more
[Mon Nov 10 19:35:53.577999 2025] [security2:error] [pid 22249:tid 140246491576000] [client 172.71.152.71:46303] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-RAY" at REQUEST_HEADERS_NAMES:Cf-Ray. [file "/etc/modsecurity/coreruleset-4.20.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "394"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-RAY found within REQUEST_HEADERS_NAMES:Cf-Ray: Cf-Ray request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Bulanan/2018/10-Infografis-Bulanan_Prakiraan_Hujan_Bulan_Desember_2018-Januari_2019-Februari_2019_Update_Dari_Analisis_Bulan_Oktober_2018.jpg"] [unique_id "aRHcKcAUVHOD-_UjH8L_7AAAkgY"] [staklim-
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-06 06:33:18
(10 months ago)
[Thu Nov 06 13:31:24.773174 2025] [security2:error] [pid 316336:tid 140567330662080] [client 172.71. ...
show more
[Thu Nov 06 13:31:24.773174 2025] [security2:error] [pid 316336:tid 140567330662080] [client 172.71.152.71:48475] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "393"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2023/02/02_Prakiraan_Curah_Hujan_Bulan_MEI_2023_di_Provinsi_Jawa_Timur-Update_dari_Analisis_Bulan_Februari_2023.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Prakiraan/03-Prakiraan-Bulanan/Prakiraan_Curah_Hujan_Bulanan/Prakiraan_Curah_Hujan_Bulanan_Provinsi_Jawa_Timur/2023
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
hermawan
2025-11-03 21:43:27
(10 months ago)
[Tue Nov 04 04:41:55.324694 2025] [security2:error] [pid 2651361:tid 140237595469504] [client 172.71 ...
show more
[Tue Nov 04 04:41:55.324694 2025] [security2:error] [pid 2651361:tid 140237595469504] [client 172.71.152.71:33327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "CF-Connecting-IP" at REQUEST_HEADERS_NAMES:Cf-Connecting-Ip. [file "/etc/modsecurity/coreruleset-4.19.0/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "378"] [id "440005"] [msg "BAD REQUEST_HEADERS_NAMES - Detected and Blocked"] [data "Matched Data: CF-Connecting-IP found within REQUEST_HEADERS_NAMES:Cf-Connecting-Ip: Cf-Connecting-Ip request_line = GET /images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg HTTP/2.0"] [severity "NOTICE"] [hostname "staklim-jatim.bmkg.go.id"] [uri "/images/Klimatologi/Infografis/Infografis-Iklim/Perubahan_Iklim/Infografis_Perubahan_Iklim_Jawa_Timur-600.jpg"] [unique_id "aQkho1gwk_Wutk3m7XLVKAACAgA"] [staklim-jatim.bmkg.go.id] [staklim-jatim.bmkg.go.id] top=[2651362] [4uCFlXeiAeo] [aQkho1gwk_Wutk3m7XLVKAACAgA] keep_
...
show less
Hacking
Web App Attack