๐บ๐ธ
etu brutus
2026-10-02 20:19:14
(51 minutes ago)
207.175.92.9 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 20:17:47
(53 minutes ago)
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-22al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 207.175.92.9 - - [02/Oct/2026:22:17:29 +0200] "GET /.ssh/config HTTP/2.0" 404 109398 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-10-02 19:02:51
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 207.175.92.9 (BE/Belgium/9.92.175.207.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 207.175.92.9 (BE/Belgium/9.92.175.207.bc.googleusercontent.com)
show less
SQL Injection
๐ฌ๐ง
consul.to
2026-10-02 18:44:08
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
venar
2026-10-02 18:41:05
(2 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-02 17:26:40
(3 hours ago)
[02/Oct/2026:13:26:35.683449 --0400] ar-pS4KZK5ivXpoAI4pOcAAAAEQ 207.175.92.9 36406 205.233.18.17 70 ...
show more
[02/Oct/2026:13:26:35.683449 --0400] ar-pS4KZK5ivXpoAI4pOcAAAAEQ 207.175.92.9 36406 205.233.18.17 7081
[02/Oct/2026:13:26:39.574584 --0400] ar-pT5yL0ha4pUb6cgDhEAAAANQ 207.175.92.9 47180 205.233.18.17 7081
[02/Oct/2026:13:26:39.585229 --0400] ar-pT9XAb1cGsI3AyLw7RQAAAxg 207.175.92.9 47192 205.233.18.17 7081
[02/Oct/2026:13:26:39.589023 --0400] ar-pT9XAb1cGsI3AyLw7RgAAAwc 207.175.92.9 47218 205.233.18.17 7081
[02/Oct/2026:13:26:39.746453 --0400] ar-pT9XAb1cGsI3AyLw7SAAAAxU 207.175.92.9 47234 205.233.18.17 7081
...
show less
Hacking
Anonymous
2026-10-02 17:19:21
(3 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
Marc
2026-10-02 16:50:54
(4 hours ago)
207.175.92.9 - - [02/Oct/2026:18:50:54 +0200] "GET /register HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Mac ...
show more
207.175.92.9 - - [02/Oct/2026:18:50:54 +0200] "GET /register HTTP/2.0" 404 291 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" 207.175.92.9 - - [02/Oct/2026:18:50:54 +0200] "GET /z9x8c7v6b5-debug-trigger-ai.vharianjenkins.com HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 207.175.92.9 - - [02/Oct/2026:18:50:54 +0200] "GET /portal HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 16:50:09
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:50:01.082438 2026] [security2:error] [pid 18763:tid 18763] [client 207.175.92.9:53726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||voidpope.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "voidpope.com"] [uri "/z9x8c7v6b5-debug-trigger-voidpope.com"] [unique_id "ar_gubGw9d-PCN2nsskx-wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:35:08
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:34:57.352955 2026] [security2:error] [pid 19506:tid 19506] [client 207.175.92.9:52370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vittariabeauty.com|F|2"] [data ".vittariabeauty.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vittariabeauty.com"] [uri "/z9x8c7v6b5-debug-trigger-www.vittariabeauty.com"] [unique_id "ar_PIQFoqS2VwyKDHaNmswAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
H24
2026-10-02 14:29:06
(6 hours ago)
/configuration.php.bak /@fs/../.env /config.php.bak /wp/.env /wp-config.php.bak /wp-config.old /conf ...
show more
/configuration.php.bak /@fs/../.env /config.php.bak /wp/.env /wp-config.php.bak /wp-config.old /config/.env.php /.env /@fs/src/.env /storage/.env
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:18:11
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:18:03.043109 2026] [security2:error] [pid 17474:tid 17474] [client 207.175.92.9:46534] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.versahealthcare.versacardio.com|F|2"] [data ".versahealthcare.versacardio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.versahealthcare.versacardio.com"] [uri "/z9x8c7v6b5-debug-trigger-www.versahealthcare.versacardio.com"] [unique_id "ar-g-3LKu5aen3u9iZqJqwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:05:01
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:04:53.594744 2026] [security2:error] [pid 7872:tid 7926] [client 207.175.92.9:41408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fevini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fevini.com"] [uri "/z9x8c7v6b5-debug-trigger-fevini.com"] [unique_id "ar-BxVv7ORXbDmQV04FPxAAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 09:56:23
(11 hours ago)
Oct 1 23:43:21 localhost kernel: [119257676.962542] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:9 ...
show more
Oct 1 23:43:21 localhost kernel: [119257676.962542] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=207.175.92.9 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=40224 DF PROTO=TCP SPT=44202 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
Oct 1 23:43:21 localhost kernel: [119257676.962575] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=207.175.92.9 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=40224 DF PROTO=TCP SPT=44202 DPT=8443 SEQ=1376441859 ACK=0 WINDOW=65320 RES=0x00 SYN URGP=0 OPT (0204058C0402080A3AEA4D64000000000103030A)
Oct 2 05:56:23 localhost kernel: [119280057.719727] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e:08:00 SRC=207.175.92.9 DST=[mungedIP2] LEN=60 TOS=0x00 PREC=0x00 TTL=58 ID=57300 DF PROTO=TCP SPT=37246 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
Oct 2 05:56:23 localhost kernel: [119280057.719765] iptables_INPUT_denied: IN=eth0 OUT= MAC=f2:3c:91:84:83:95:00:00:0c:9f:f0:1e
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-02 09:11:48
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.92.9 (9.92.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:11:41.118092 2026] [security2:error] [pid 7433:tid 7433] [client 207.175.92.9:45074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||verenacastle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "verenacastle.com"] [uri "/z9x8c7v6b5-debug-trigger-verenacastle.com"] [unique_id "ar91TVBqCNcA9keXrHJxNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack