๐ฎ๐ฉ
Diskominfo Lumajang
2026-09-13 12:55:06
(14 hours ago)
Security Event Detected by SOC Diskominfo Lumajang: event=alert, hits=3
Brute-Force
๐ซ๐ท
dynamix
2026-09-12 22:29:56
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
MPL
2026-09-04 01:18:00
(1 week ago)
tcp/443 (5 or more attempts)
Port Scan
๐ช๐ธ
el-brujo
2026-09-01 18:41:54
(1 week ago)
01/Sep/2026:20:41:53.837413 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
01/Sep/2026:20:41:53.837413 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.71.232.94] ModSecurity: collections_remove_stale: Failed to access DBM file "/var/lib/mod_security/\\\\xf0\\\\xf4\\\\xd7`kU-ip": Too many open files [hostname "warzone.elhacker.net"] [uri "/"] [unique_id "apcccZ9lhTJNNhUMUR024AAVJkg"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:54:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:54:39.851620 2026] [security2:error] [pid 9659:tid 9659] [client 172.71.232.94:11615] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewaywework.com"] [uri "/.git/HEAD"] [unique_id "apZaj_YLdv-hMkigugZU_AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:31:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:31:28.995955 2026] [security2:error] [pid 31986:tid 31986] [client 172.71.232.94:9352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beckerbrokerage.net"] [uri "/.git/HEAD"] [unique_id "apJEgDKu7CSGQMsG2ewojAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-28 02:04:42
(2 weeks ago)
[FriAug2804:04:39.4421192026][security2:error][pid1996345:tid1996419][client172.71.232.94:0]ModSecur ...
show more
[FriAug2804:04:39.4421192026][security2:error][pid1996345:tid1996419][client172.71.232.94:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.rebirthing-lugano.ch\"][uri\"/.git/HEAD\"][unique_id\"apDstzJHsq6D8t4w55m6fgAAAIs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:56:28
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:56:23.643824 2026] [security2:error] [pid 6644:tid 6644] [client 172.71.232.94:10921] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mpservice.com.sv"] [uri "/.git/config"] [unique_id "apDqx3ABc0nZPIturBF0PQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:03:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:03:11.315724 2026] [security2:error] [pid 24033:tid 24033] [client 172.71.232.94:10183] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pikcasa.com"] [uri "/.git/HEAD"] [unique_id "apDeT04jxiftNs15_1tpOQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 10:14:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:13:56.708987 2026] [security2:error] [pid 8898:tid 8898] [client 172.71.232.94:12674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jeanniemorrislaw.com"] [uri "/.git/HEAD"] [unique_id "apAN5Ac9g_oxYg1ZnaS-SQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:02:25
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:02:19.559851 2026] [security2:error] [pid 84423:tid 84434] [client 172.71.232.94:10741] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fandginsurancellc.antidote-it.com"] [uri "/.git/config"] [unique_id "ao7x64ia_pCg3DDvs795EQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 17:48:43
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:48:38.489444 2026] [security2:error] [pid 1801:tid 1801] [client 172.71.232.94:13543] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.xyncom.com"] [uri "/.git/HEAD"] [unique_id "ao3VdrWSXV9rPRPgYtG5nQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-25 15:23:22
(2 weeks ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-25 12:59:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:59:39.442291 2026] [security2:error] [pid 30539:tid 30539] [client 172.71.232.94:11157] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.deborbon.me"] [uri "/.git/HEAD"] [unique_id "ao2Ru8_lBuyDkzLv7b-NlAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 08:31:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.232.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:31:12.970723 2026] [security2:error] [pid 28332:tid 28332] [client 172.71.232.94:11804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buynorthwest.com"] [uri "/.git/config"] [unique_id "ao1S0K750H9lWawF2e7PTwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack