๐บ๐ธ
WellSpring
2026-06-09 13:56:48
(1 day ago)
wordpress scan on emptyboxes.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security la ...
show more
wordpress scan on emptyboxes.org/wp-admin/install.php โ WellSpr.ing/NetSentinel civic-AI security layer
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
CBJ
2026-04-07 11:04:16
(2 months ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ซ๐ท
dynamix
2026-04-07 05:12:30
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dwmp
2026-04-06 17:37:47
(2 months ago)
[06/Apr/2026:19:37:45.375046 +0200] adPvaZT5nnBTneMl1RgSvQAAAM4 172.71.164.100 56724 38.242.227.117 ...
show more
[06/Apr/2026:19:37:45.375046 +0200] adPvaZT5nnBTneMl1RgSvQAAAM4 172.71.164.100 56724 38.242.227.117 7081
[06/Apr/2026:19:37:45.439128 +0200] adPvaYWiaVTG7n5ua8daPQAAAFA 172.71.164.100 56738 38.242.227.117 7081
[06/Apr/2026:19:37:45.457164 +0200] adPvaYWiaVTG7n5ua8daPgAAAFQ 172.71.164.100 56742 38.242.227.117 7081
...
show less
Brute-Force
SSH
๐บ๐ธ
mnsf
2026-04-05 00:05:17
(2 months ago)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-04 20:09:50
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 16:09:36.031687 2026] [security2:error] [pid 723:tid 723] [client 172.71.164.100:13958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.citizensforsanity.com"] [uri "/.git/logs/HEAD"] [unique_id "adFwAAW-dUwVeH_yNj4DKAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-04-04 14:52:51
(2 months ago)
Login credentials theft attempt
Hacking
๐ซ๐ฎ
mnazibo
2026-04-04 00:34:02
(2 months ago)
Date: Apr 04 03:33:56
Reported IP: 172.71.164.100 mod_security
id:958291
DE/Germany/-
Connections: 5 ...
show more
Date: Apr 04 03:33:56
Reported IP: 172.71.164.100 mod_security
id:958291
DE/Germany/-
Connections: 5
Blocked: Permanent Block: [LF_MODSEC]
Logs: [Sat Apr 04 03:33:56.353290 2026] [:error] [pid 6910:tid 6965] [client 172.71.164.100:11320] [client 172.71.164.100] ModSecurity: Access denied with code 403 (phase 2). String match "bytes=0-" at REQUEST_HEADERS:Range. [file "/usr/local/apache/modsecurity-owasp-old/base_rules/modsecurity_crs_20_protocol_violations.conf"] [line "428"] [id "958291"] [rev "2"] [msg "Range: field exists and begins with 0."] [data "bytes=0-1500"] [severity "WARNING"] [ver "OWASP_CRS/2.2.9"] [maturity "6"] [accuracy "8"] [tag "OWASP_CRS/PROTOCOL_VIOLATION/INVALID_HREQ"] [hostname "ns2.my_domain"] [uri "/.git/config"] [unique_id "adBcdAVede3VAK-cvo_ISAAAAEo"]
[Sat Apr 04 03:33:56.421254 2026] [:error] [pid 6910:tid 6949] [client 172.71.164.100:11320] [client 172.71.164.100] ModSecurity: Access denied with code 403 (phase 2). String match "bytes=0-" at REQUEST_HEADER
show less
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-04-03 22:28:32
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 13:19:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 09:19:50.329773 2026] [security2:error] [pid 17941:tid 17941] [client 172.71.164.100:11281] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.creativeinteriors.co.com"] [uri "/config/.env"] [unique_id "ac--dujW8ky1ykQmAJwObQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
omartin
2026-04-03 11:34:12
(2 months ago)
Critical Vulnerability Scan detected
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 01:29:15
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 21:29:09.123772 2026] [security2:error] [pid 27699:tid 27715] [client 172.71.164.100:9814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.aceelectricalsupplies.com"] [uri "/.env.dev"] [unique_id "ac8X5VOXDUiZ47X6Yf3zPQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-04-02 21:02:10
(2 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-02 20:51:48
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.100 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 02 16:51:39.757075 2026] [security2:error] [pid 5071:tid 5071] [client 172.71.164.100:11594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.istartech.hk"] [uri "/.git/refs/heads/main"] [unique_id "ac7W2zGWi8frSgO_ANRW0AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-02 06:44:42
(2 months ago)
Multiple WAF Violations
Web App Attack