๐ฉ๐ช
LRob
2026-09-15 09:44:07
(17 hours ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-15 09:44 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 09:39:35
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:39:27.530788 2026] [security2:error] [pid 17981:tid 17981] [client 31.97.228.124:43648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcga.golf"] [uri "/wp-config.php.old"] [unique_id "aqkST49Z3rNp-xrjiF6rhwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-15 06:24:52
(20 hours ago)
31.97.228.124 - - [15/Sep/2026:08:24:52 +0200] "GET /.git/config HTTP/1.1" 302 419 "-" "Mozilla/5.0 ...
show more
31.97.228.124 - - [15/Sep/2026:08:24:52 +0200] "GET /.git/config HTTP/1.1" 302 419 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-15 06:22:45
(20 hours ago)
[TueSep1508:22:41.0547352026][security2:error][pid2861735:tid2861868][client31.97.228.124:0]ModSecur ...
show more
[TueSep1508:22:41.0547352026][security2:error][pid2861735:tid2861868][client31.97.228.124:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"assistenza-pc-mac-ticino.artisteer-italia.org\"][uri\"/.git/config\"][unique_id\"aqjkMRJoUHRyBDmX0yru-QAAARY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 04:45:40
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:45:36.112261 2026] [security2:error] [pid 29821:tid 29821] [client 31.97.228.124:41870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aroilcontrolsystem.com"] [uri "/.git/config"] [unique_id "aqjNcAXuZXA5tn6CREaEGAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 03:10:02
(23 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 20:58:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:58:25.895550 2026] [security2:error] [pid 13738:tid 13738] [client 31.97.228.124:51024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alianzafreight.com"] [uri "/.git/config"] [unique_id "aqhf8atzkPLClvVMfMwAdQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-14 19:57:20
(1 day ago)
๐ Probes for tons of inexistent files and/or PHP scripts
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-14 17:59:35
(1 day ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-14 17:59 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-14 11:12:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 07:12:28.609613 2026] [security2:error] [pid 13464:tid 13464] [client 31.97.228.124:57660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerielster.com"] [uri "/wp-config.php.swp"] [unique_id "aqfWnJ5L-NUfPJpmWkhQBQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 10:35:06
(1 day ago)
WAPPICOM WEBEXPLOIT 31.97.228.124 (srv941197.hstgr.cloud)
Web App Attack
๐บ๐ธ
cwytech
2026-09-14 05:31:46
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 01:40:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 21:40:44.853079 2026] [security2:error] [pid 5410:tid 5410] [client 31.97.228.124:60388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casadelsolmexico.net"] [uri "/wp-config.php.orig"] [unique_id "aqdQnNL2qsNbLINlnkWMcgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 21:07:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the ...
show more
(mod_security) mod_security (id:210492) triggered by 31.97.228.124 (srv941197.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:07:14.864911 2026] [security2:error] [pid 5731:tid 5850] [client 31.97.228.124:54732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magusincognito.com"] [uri "/wp-config.php~"] [unique_id "aqcQgst_p-F9ymNwmpxntgAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 15:24:33
(2 days ago)
2026/09/13 15:23:30 [error] 199232#199232: *508979 [client 31.97.228.124] ModSecurity: Access denied ...
show more
2026/09/13 15:23:30 [error] 199232#199232: *508979 [client 31.97.228.124] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "aobandassociates.com"] [uri "/wp-config.php.old"] [unique_id "178931301063.803296"] [ref ""], client: 31.97.228.124, server: aobandassociates.com, request: "GET /wp-config.php.old HTTP/1.1", host: "aobandassociates.com"
2026/09/13 15:24:31 [error] 199232#199232: *508994 [client 31.97.228.124] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5
...
show less
Brute-Force