๐ณ๐ฑ
tpjg
2026-07-25 18:43:52
(17 hours ago)
Automated: 15 requests with error status in 120s window from 20.127.239.246.
Evidence: /.aws/config: ...
show more
Automated: 15 requests with error status in 120s window from 20.127.239.246.
Evidence: /.aws/config:301,/wp-config.php.bak:301,/.env.development:301,/.env_production:301,/.env.bak:301,/.env.old:301,/.env.prod:301,/.env.backup:301,/.env.production:301,/.env.local:301,/.env:301,/.git/index:301,/.git/refs/heads/main:301,/.git/config:301,/.git/HEAD:301
show less
Web App Attack
Anonymous
2026-07-25 18:33:56
(17 hours ago)
20.127.239.246 - - [25/Jul/2026:18:33:54 +0000] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 ( ...
show more
20.127.239.246 - - [25/Jul/2026:18:33:54 +0000] "GET /.git/HEAD HTTP/1.1" 404 134 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
20.127.239.246 - - [25/Jul/2026:18:33:55 +0000] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-25 17:49:49
(18 hours ago)
15 attempts against mh-modsecurity-ban on solar
Brute-Force
Web App Attack
Anonymous
2026-07-25 16:06:53
(19 hours ago)
denied traffic to a honeypot network. destination port 2078.
Port Scan
Hacking
๐บ๐ธ
MPL
2026-07-25 15:37:01
(20 hours ago)
tcp port scan (10 or more attempts)
Port Scan
๐บ๐ธ
IndigoRidge
2026-07-25 15:22:04
(20 hours ago)
20.127.239.246 - - [25/Jul/2026:11:21:41 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
20.127.239.246 - - [25/Jul/2026:11:21:41 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0"
20.127.239.246 - - [25/Jul/2026:11:21:48 -0400] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36"
20.127.239.246 - - [25/Jul/2026:11:22:04 -0400] "GET /.aws/credentials HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ต๐ฑ
webadmin
2026-07-25 15:16:15
(20 hours ago)
Web App Attack
๐ฉ๐ช
strxmpp
2026-07-25 14:41:56
(21 hours ago)
20.127.239.246 - - [25/Jul/2026:16:41:55 +0200] "GET /.git/HEAD HTTP/1.1" 404 495 "-" "Mozilla/5.0 ( ...
show more
20.127.239.246 - - [25/Jul/2026:16:41:55 +0200] "GET /.git/HEAD HTTP/1.1" 404 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-25 13:58:37
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.127.239.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.239.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:58:32.267425 2026] [security2:error] [pid 9389:tid 9389] [client 20.127.239.246:12768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.18"] [uri "/.git/HEAD"] [unique_id "amTBCCJ6pQQCKFNnbQopeAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 13:20:53
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 20.127.239.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 20.127.239.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 09:20:49.875461 2026] [security2:error] [pid 1358487:tid 1358487] [client 20.127.239.246:11526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.38"] [uri "/.git/config"] [unique_id "amS4MYI8x0qv7IBGzcfm9gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
FEWA
2026-07-15 19:04:36
(1 week ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 13:35:52
(1 month ago)
Spring.Boot.Actuator.Unauthorized.Access
Open Proxy
๐ง๐ท
ludarkstar99
2026-06-14 21:45:02
(1 month ago)
Blocked by os-abuseipdb; 5 hits, proto=tcp, ports=2083,443,80,8080,8443
Port Scan
Hacking
๐ธ๐ช
SkyDancer
2026-06-14 17:13:13
(1 month ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐บ๐ธ
Axel
2026-06-14 17:03:14
(1 month ago)
Blocked by UFW on MVI [8080/tcp] | SPT: 3120 | TTL: 48 | LEN: 60 | TOS: 0x00 โข Reported by: github.c ...
show more
Blocked by UFW on MVI [8080/tcp] | SPT: 3120 | TTL: 48 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan