๐ซ๐ท
dynamix
2026-06-25 23:55:54
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐ฉ
gonet.home
2026-06-24 01:31:16
(1 day ago)
Security Event Detected by SOC Gonet: event=alert, hits=1
Brute-Force
Anonymous
2026-06-23 14:18:01
(2 days ago)
[Tue Jun 23 16:18:00.078619 2026] [authz_core:error] [pid 3415] [client 172.71.95.132:11864] AH01630 ...
show more
[Tue Jun 23 16:18:00.078619 2026] [authz_core:error] [pid 3415] [client 172.71.95.132:11864] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 23 16:18:00.201037 2026] [authz_core:error] [pid 3415] [client 172.71.95.132:11864] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Tue Jun 23 16:18:00.321664 2026] [authz_core:error] [pid 3415] [client 172.71.95.132:11864] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
Anonymous
2026-06-21 00:28:44
(5 days ago)
[Sun Jun 21 02:28:42.510161 2026] [authz_core:error] [pid 29494] [client 172.71.95.132:12672] AH0163 ...
show more
[Sun Jun 21 02:28:42.510161 2026] [authz_core:error] [pid 29494] [client 172.71.95.132:12672] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Jun 21 02:28:42.576175 2026] [authz_core:error] [pid 29494] [client 172.71.95.132:12672] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Jun 21 02:28:42.651932 2026] [authz_core:error] [pid 29494] [client 172.71.95.132:12672] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 02:22:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 22:21:57.581317 2026] [security2:error] [pid 26302:tid 26302] [client 172.71.95.132:12973] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notaryfoundation.ic1.biz"] [uri "/.git/config"] [unique_id "ajX5RcKdGbHsSkkR3Au50wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-19 23:48:28
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 15:38:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 11:38:26.960515 2026] [security2:error] [pid 16743:tid 16743] [client 172.71.95.132:12513] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wetheparty.org.stlouisdave.com"] [uri "/.env"] [unique_id "ajAccqBbdam98NkWd-_6iAAAAB8"], referer: https://www.google.com/search?q=www.wetheparty.org.stlouisdave.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-05-29 21:06:24
(3 weeks ago)
Abuse Detected (9)
Brute-Force
Web App Attack
Anonymous
2026-05-28 01:08:12
(4 weeks ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐ฉ๐ช
Blexyel
2026-05-25 14:47:51
(1 month ago)
172.71.95.132 - - [25/May/2026:16:47:40 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
172.71.95.132 - - [25/May/2026:16:47:40 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 13 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-05-22 01:55:50
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-20 13:17:34
(1 month ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-05-16 18:43:11
(1 month ago)
[Sat May 16 20:43:10.044056 2026] [authz_core:error] [pid 32417] [client 172.71.95.132:10528] AH0163 ...
show more
[Sat May 16 20:43:10.044056 2026] [authz_core:error] [pid 32417] [client 172.71.95.132:10528] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 16 20:43:10.333190 2026] [authz_core:error] [pid 32417] [client 172.71.95.132:10528] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sat May 16 20:43:10.616766 2026] [authz_core:error] [pid 32417] [client 172.71.95.132:10528] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 09:06:43
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.95.132 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 05:06:27.230478 2026] [security2:error] [pid 11943:tid 11943] [client 172.71.95.132:10404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.easyhousecash.com"] [uri "/.env.dev"] [unique_id "aggzk1zXdEwmbLpfkJypigAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mawan
2026-05-13 03:24:01
(1 month ago)
Suspected of having performed illicit activity on LAX server.
Web App Attack