Anonymous
2026-06-25 21:01:55
(1 day ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฌ๐ง
Don Felip
2026-06-25 20:10:49
(1 day ago)
Web Exploiter - Banned by Fail2Ban
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 19:32:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 15:32:27.592449 2026] [security2:error] [pid 17617:tid 17617] [client 20.231.101.34:18739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.197"] [uri "/.git/HEAD"] [unique_id "aj2CS7Y-DeKYslULD2ZY9gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 18:40:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 14:40:49.696957 2026] [security2:error] [pid 30937:tid 30937] [client 20.231.101.34:18841] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.166"] [uri "/.git/HEAD"] [unique_id "aj12MfmmaSPoU0nuO_Y00gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 18:39:28
(1 day ago)
*Port Scan* detected from 20.231.101.34 (US/United States/-). 5 hits in the last 10 seconds
Brute-Force
Port Scan
๐ฌ๐ง
PeravixGroup
2026-06-02 07:17:48
(3 weeks ago)
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. A ...
show more
Honeypot detection: Web application scanning / reconnaissance attempt on port 8080. Severity: LOW. Aaran.cloud
show less
Port Scan
Bad Web Bot
๐ฉ๐ช
kkeyser
2026-06-02 06:49:22
(3 weeks ago)
GET /.env.local HTTP/1.1
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:36:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:35:57.793173 2026] [security2:error] [pid 31542:tid 31562] [client 20.231.101.34:65095] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.134"] [uri "/.git/HEAD"] [unique_id "ah55zWg01fv_BglerYrjiwAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-02 06:32:57
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
cwytech
2026-06-02 05:39:33
(3 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-probing.
Bad Web Bot
Web App Attack
๐บ๐ธ
vanguardm
2026-06-02 03:40:04
(3 weeks ago)
Automated report: 34 events detected. Types: web-attack
Web App Attack
๐ง๐ท
SOC PR
2026-06-02 03:28:25
(3 weeks ago)
IPS: IKE Enforcement Violation.
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 03:25:42
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 20.231.101.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 23:25:37.763651 2026] [security2:error] [pid 3588:tid 3588] [client 20.231.101.34:65155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.147"] [uri "/.git/HEAD"] [unique_id "ah5NMQjAyM9cPe0fywRXXgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 03:19:12
(3 weeks ago)
Drop from IP address 20.231.101.34 to tcp-port 2083
Port Scan
๐บ๐ธ
ISPLtd
2026-06-02 02:52:12
(3 weeks ago)
Jun 1 20:52:11 20.231.101.34 TCP SPT=65417 DPT=2087 SYN
Jun 1 20:52:11 20.231.101.34 TCP SPT=65418 ...
show more
Jun 1 20:52:11 20.231.101.34 TCP SPT=65417 DPT=2087 SYN
Jun 1 20:52:11 20.231.101.34 TCP SPT=65418 DPT=2082 SYN
Jun 1 20:52:11 20.231.101.34 TCP SPT=65415 DPT=8080
...
show less
Port Scan