๐ฟ๐ฆ
conure.sh
2026-09-22 12:04:05
(2 days ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 2 domain(s) in 1s
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-22 04:23:49
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:33:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:33:33.831221 2026] [security2:error] [pid 2619:tid 2619] [client 178.128.205.227:37312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "francesphilosophy.cygnetsilks.com"] [uri "/.git/config"] [unique_id "arHM3XeapNuooB9i7j7Z5QAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-22 00:25:44
(3 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 178.128.205.227 (DE/Germany/-): 1 in the ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 178.128.205.227 (DE/Germany/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 178.128.205.227 - - [22/Sep/2026:02:25:43 +0200] "POST //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php HTTP/2.0" 200 4846 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" "178.128.205.227" host=francescadandrea.com
show less
Port Scan
๐ซ๐ท
Octopuce
2026-09-22 00:19:22
(3 days ago)
Aggressive web search of vulnerable pages: //assets/plugins/jQuery-File-Upload/server/php/ //static/ ...
show more
Aggressive web search of vulnerable pages: //assets/plugins/jQuery-File-Upload/server/php/ //static/lib/jquery-file-upload/server/php/ //assets ...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 22:15:34
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:10:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:10:20.837365 2026] [security2:error] [pid 25307:tid 25307] [client 178.128.205.227:42768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foxmm.com"] [uri "/.git/config"] [unique_id "arGrTL75h92ESUp5MaoqZwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:15:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:15:39.113715 2026] [security2:error] [pid 15310:tid 15310] [client 178.128.205.227:53180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fourdogsandadrone.celtickyss.com"] [uri "/.git/config"] [unique_id "arGee_3PcwCgElFPWCW8UwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:37:28
(3 days ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 19:45:02
(3 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 19:20:27
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-21 19:16:08
(3 days ago)
[Mon Sep 21 15:16:04.190258 2026] [security2:error] [pid 29467:tid 29500] [client 178.128.205.227:33 ...
show more
[Mon Sep 21 15:16:04.190258 2026] [security2:error] [pid 29467:tid 29500] [client 178.128.205.227:33728] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "forum.yorknation.com"] [uri "/.git/config"] [unique_id "arGCdEzJLLwFA95HV0I8kwAAAMU"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:13:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.205.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:13:00.493140 2026] [security2:error] [pid 15072:tid 15072] [client 178.128.205.227:60222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forum.whodatnation.com"] [uri "/.git/config"] [unique_id "arGBvBTAVoiw4HoX75jmOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-09-21 19:06:00
(3 days ago)
IPBlock protected site ID [4730-fr].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-21 18:46:25
(3 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack