๐บ๐ธ
mawan
2026-06-25 09:11:54
(2 days ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-23 02:45:53
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ท๐บ
DZBOT
2026-06-21 10:45:30
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 06:47:54
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 02:47:51.208031 2026] [security2:error] [pid 8158:tid 8164] [client 172.71.164.45:11651] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gafmboard.aafm.us"] [uri "/.env"] [unique_id "ajeJFywrBuCqNMKCKf_0swAAAEQ"], referer: https://www.google.com/search?q=www.gafmboard.aafm.us
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-06-20 16:42:10
(1 week ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-11 11:29:13
(2 weeks ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Ob ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_admin. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-08 22:26:58
(2 weeks ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-07 22:26:24
(2 weeks ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 14:26:32
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 10:26:25.245331 2026] [security2:error] [pid 22489:tid 22489] [client 172.71.164.45:13471] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arnebowman.com"] [uri "/.git/config"] [unique_id "aiV_kWsfKqGAAeCcVZ54lAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 01:59:36
(2 weeks ago)
Fail2Ban triggered
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-07 00:53:31
(2 weeks ago)
-:443 172.71.164.45 - - [07/Jun/2026:02:53:30 +0200] - "GET /.git/config HTTP/2.0" 404 2233 "-" "Moz ...
show more
-:443 172.71.164.45 - - [07/Jun/2026:02:53:30 +0200] - "GET /.git/config HTTP/2.0" 404 2233 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:127.0) Gecko/20100101 Firefox/127.0"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 21:39:56
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 17:39:51.534367 2026] [security2:error] [pid 5506:tid 5506] [client 172.71.164.45:13365] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mastersonsmotel.ca"] [uri "/.git/config"] [unique_id "aiCfJ6hq_RNSWy4pM6Co4QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 20:39:38
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 16:39:32.990248 2026] [security2:error] [pid 10825:tid 10825] [client 172.71.164.45:13758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vittariahealth.com"] [uri "/.git/config"] [unique_id "ah8_hDx7ugG4w4u_4U_MxgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 16:38:58
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:38:51.420894 2026] [security2:error] [pid 10808:tid 10817] [client 172.71.164.45:9360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slelectric.com"] [uri "/.git/config/"] [unique_id "ah8HG_uMbMOR3_QGgRaqggAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 10:21:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.164.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:21:27.422052 2026] [security2:error] [pid 2058:tid 2079] [client 172.71.164.45:10299] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charteredfinancialmanager.com"] [uri "/.git/config"] [unique_id "ah6up0g5-kr3PBiLqLpmqgAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack