πΊπΈ
gu-alvareza
2026-06-03 07:05:19
(1 week ago)
HTPasswd.Access
Brute-Force
π·πΈ
Scan
2026-06-03 00:27:36
(1 week ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
Anonymous
2026-06-02 23:00:00
(1 week ago)
SSH Brute-Force
DDoS Attack
Port Scan
Hacking
Brute-Force
SSH
π¦πΉ
urnilxfgbez
2026-06-02 22:45:00
(1 week ago)
Last 24 Hours suspicious: (DPT=445|DPT=3389|DPT=22|DPT=3306|DPT=8080|DPT=23|DPT=5900|DPT=1433)
Port Scan
π―π΅
mkaraki
2026-06-02 21:12:22
(1 week ago)
1780434741 # Service_probe # SIGNATURE_SEND # source_ip:20.102.103.199 # dst_port:80
...
Port Scan
πΊπΈ
TPI-Abuse
2026-06-02 21:05:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 17:05:10.680771 2026] [security2:error] [pid 31940:tid 31940] [client 20.102.103.199:48814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.143"] [uri "/.git/HEAD"] [unique_id "ah9FhgI7QxYBhjW--9AUgQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
micropedro
2026-06-02 20:41:10
(1 week ago)
6 incidents: web scanning/attack, port scanning. Ports: 2082/TCP(1), 2087/TCP(1), 8080/TCP(1), 8443/ ...
show more
6 incidents: web scanning/attack, port scanning. Ports: 2082/TCP(1), 2087/TCP(1), 8080/TCP(1), 8443/TCP(1). First: 2026-06-02 16:41, Last: 2026-06-02 16:41 UTC. Triggers: non-public-port,port-trap,ufw-repeater,recidive,firewall-http,firewall-tcp.
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 20:07:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 16:07:37.488051 2026] [security2:error] [pid 18178:tid 18178] [client 20.102.103.199:49163] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.148"] [uri "/.env"] [unique_id "ah84CdOO__ow5L3_bhyj_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
SkyDancer
2026-06-02 19:34:09
(1 week ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
πΊπΈ
pixiekat
2026-06-02 18:39:42
(1 week ago)
[Tue Jun 02 18:39:33.889372 2026] [authz_core:error] [pid 72840:tid 72863] [client 20.102.103.199:48 ...
show more
[Tue Jun 02 18:39:33.889372 2026] [authz_core:error] [pid 72840:tid 72863] [client 20.102.103.199:48708] AH01630: client denied by server configuration: /var/www/html/.env
[Tue Jun 02 18:39:35.505221 2026] [authz_core:error] [pid 72840:tid 72864] [client 20.102.103.199:48764] AH01630: client denied by server configuration: /var/www/html/.env.local
[Tue Jun 02 18:39:36.032009 2026] [authz_core:error] [pid 72868:tid 72871] [client 20.102.103.199:48757] AH01630: client denied by server configuration: /var/www/html/.env.production
[Tue Jun 02 18:39:37.166138 2026] [authz_core:error] [pid 72868:tid 72894] [client 20.102.103.199:48714] AH01630: client denied by server configuration: /var/www/html/.env.backup
[Tue Jun 02 18:39:42.445727 2026] [authz_core:error] [pid 72868:tid 72880] [client 20.102.103.199:48710] AH01630: client denied by server configuration: /var/www/html/wp-config.php.bak
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-02 18:31:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:31:02.964968 2026] [security2:error] [pid 32503:tid 32503] [client 20.102.103.199:48537] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.168"] [uri "/.git/config"] [unique_id "ah8hZtsy9_YKYhng58v0MgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
PeravixGroup
2026-06-02 18:21:54
(1 week ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8443. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8443. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
π«π·
GabrielJST
2026-06-02 18:20:09
(1 week ago)
*Port Scan* detected from 20.102.103.199 (US/United States/-).
Port Scan
π«π·
dynamix
2026-06-02 17:48:11
(1 week ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 17:47:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.102.103.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:47:19.888450 2026] [security2:error] [pid 15684:tid 15684] [client 20.102.103.199:48911] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.160"] [uri "/.env.backup"] [unique_id "ah8XJ4PPSspn-fX1yn3MSAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack