๐บ๐ธ
TPI-Abuse
2026-07-27 20:43:41
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 209.99.189.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 209.99.189.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:43:27.086607 2026] [security2:error] [pid 4013849:tid 4013849] [client 209.99.189.125:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/app/etc/local.xml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avaliantlife.com"] [uri "/app/etc/local.xml"] [unique_id "amfC73bYOpMFix_obAZG1wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hchristo
2026-07-27 20:43:24
(12 minutes ago)
[Mon Jul 27 22:43:23.635442 2026] [authz_core:error] [pid 16980:tid 17067] [client 209.99.189.125:51 ...
show more
[Mon Jul 27 22:43:23.635442 2026] [authz_core:error] [pid 16980:tid 17067] [client 209.99.189.125:51376] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/das-fishing.de/buchhaltung.das-fishing.de/.circleci
[Mon Jul 27 22:43:24.360659 2026] [authz_core:error] [pid 16980:tid 17078] [client 209.99.189.125:51376] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/das-fishing.de/buchhaltung.das-fishing.de/.circleci
[Mon Jul 27 22:43:24.378252 2026] [authz_core:error] [pid 16980:tid 17065] [client 209.99.189.125:51376] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/das-fishing.de/buchhaltung.das-fishing.de/.gitlab-ci.yml
[Mon Jul 27 22:43:24.395249 2026] [authz_core:error] [pid 16980:tid 17049] [client 209.99.189.125:51376] AH01630: client denied by server configuration: /var/www/kd1103/htdocs/das-fishing.de/buchhaltung.das-fishing.de/.gitlab-ci.yaml
[Mon Jul 27 22:43:24.447263 2026] [authz_core:error] [pid 16980:tid 17042] [c
...
show less
Brute-Force
๐ซ๐ฎ
JLKnoch Software GmbH
2026-07-27 20:23:08
(33 minutes ago)
CrowdSec crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
antlac1
2026-07-27 20:01:47
(54 minutes ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-27 19:59:05
(57 minutes ago)
209.99.189.125 - - [27/Jul/2026:22:59:04 +0300] "GET /.gitlab-ci.yml HTTP/1.1" 404 729 "-" "Mozilla/ ...
show more
209.99.189.125 - - [27/Jul/2026:22:59:04 +0300] "GET /.gitlab-ci.yml HTTP/1.1" 404 729 "-" "Mozilla/5.0 (compatible; SecurityResearch/1.0)"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-07-27 19:55:35
(1 hour ago)
2026/07/27 19:55:32 [error] 4144894#4144894: *418187855 access forbidden by rule, client: 209.99.189 ...
show more
2026/07/27 19:55:32 [error] 4144894#4144894: *418187855 access forbidden by rule, client: 209.99.189.125, server: bonocom.org, request: "GET /.travis.yml HTTP/2.0", host: "bonocom.org"
2026/07/27 19:55:33 [error] 4144890#4144890: *418187875 access forbidden by rule, client: 209.99.189.125, server: bonocom.org, request: "GET /.travis.yaml HTTP/2.0", host: "bonocom.org"
2026/07/27 19:55:33 [error] 4144890#4144890: *418187880 access forbidden by rule, client: 209.99.189.125, server: bonocom.org, request: "GET /.circleci/config.yml HTTP/2.0", host: "bonocom.org"
...
show less
Web App Attack
๐ซ๐ฎ
Kimmo Rieskaniemi
2026-07-27 19:32:51
(1 hour ago)
CrowdSec triggered crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-07-27 19:32:18
(1 hour ago)
(PERMBLOCK) 209.99.189.125 (US/United States/-) has had more than 4 temp blocks in the last 86400 se ...
show more
(PERMBLOCK) 209.99.189.125 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ต๐ฑ
Niko's Stuff
2026-07-27 19:16:37
(1 hour ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/209.99.189.1 ...
show more
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/209.99.189.125
show less
Web App Attack
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-07-27 19:13:31
(1 hour ago)
Probing websites for vulnerabilities
Web App Attack
๐ฎ๐น
mediarama.com
2026-07-27 19:07:58
(1 hour ago)
Banned by Fail2Ban
Web App Attack
๐ซ๐ท
ACE-INFORMATIQUE.NC
2026-07-27 19:00:06
(1 hour ago)
Web App Attack blocked by Fail2ban
Web App Attack
๐ต๐ฑ
Budyn
2026-07-27 18:44:40
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: URI: /.gitlab-ci.yml | UA: Mozilla/5.0 (compatible; SecurityResearch/1.0) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
c y
2026-07-27 18:33:10
(2 hours ago)
Security Monitor detected: sensitive_path_access
Port Scan
๐ฉ๐ช
webanyone
2026-07-27 18:30:58
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack