๐ฎ๐น
Progetto1
2026-09-02 22:40:02
(4 minutes ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 21:46:42
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 17:46:38.103158 2026] [security2:error] [pid 6130:tid 6130] [client 43.199.173.119:50110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arofish.us"] [uri "/.git/config"] [unique_id "apiZPmmumx6plWvW0-7kywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-02 20:48:46
(1 hour ago)
2026-09-02 20:48:11 POST /err/ 404;https://clinicadurand.com.br:443/wp-json/batch/v1 - 43.199.173.11 ...
show more
2026-09-02 20:48:11 POST /err/ 404;https://clinicadurand.com.br:443/wp-json/batch/v1 - 43.199.173.119 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 245
2026-09-02 20:48:14 POST /err/ 404;https://clinicadurand.com.br:443/index.php?rest_route=/batch/v1 - 43.199.173.119 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 245
2026-09-02 20:48:16 POST /err/ 404;https://clinicadurand.com.br:443/index.php/wp-json/batch/v1 - 43.199.173.119 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 245
2026-09-02 20:48:22 POST /err/ 404;https://clinicadurand.com.br:443/index.php - 43.199.173.119 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/126.0.0.0+Safari/537.36 - 403 245
...
show less
Web App Attack
๐ท๐ด
iulianh
2026-09-02 19:40:41
(3 hours ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-02 16:23:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:23:52.559201 2026] [security2:error] [pid 6655:tid 6655] [client 43.199.173.119:60544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thereisaplaceonearth.com"] [uri "/wp-config.php.bak"] [unique_id "aphNmA4zWltHJQnFe0xZkAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-02 15:46:53
(6 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 15:17:56
(7 hours ago)
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-09 ...
show more
Enumerating paths that do not exist (scanning) | method: GET (+1 more) | path: / (+3 more) | 2026-09-02 15:17 UTC
show less
Port Scan
Web App Attack
๐ช๐ธ
alferez
2026-09-02 14:12:43
(8 hours ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-02 13:05:12
(9 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-02 12:42:43
(10 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
Anonymous
2026-09-02 12:35:01
(10 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-02 12:24:47
(10 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 85>=65, Abuse 100, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:13:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 43.199.173.119 (ec2-43-199-173-119.ap-east-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:13:10.011362 2026] [security2:error] [pid 24528:tid 24544] [client 43.199.173.119:59656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultbaja.com"] [uri "/.git/config"] [unique_id "apgS1tCqdx2itzrOPVPfPgAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-02 11:48:05
(10 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-02T11:47:53.633596736Z. Context: http_status=302
show less
Web App Attack
๐ต๐ฑ
Budyn
2026-09-02 11:34:00
(11 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: admin.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack