๐ณ๐ฑ
soverin
2026-07-26 08:23:03
(2 months ago)
spam
Email Spam
๐ณ๐ฑ
homeshowdomain.nl
2026-01-02 22:59:07
(9 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-01.
show less
Hacking
Web App Attack
SSH
๐ง๐ช
boxed-it
2026-01-02 20:04:42
(9 months ago)
GET /.git/config (Tarpitted for 1d15h8m30s, wasted 8.06MB)
Web App Attack
๐ง๐ช
sid3windr
2026-01-02 17:13:28
(9 months ago)
GET /.git/config (Tarpitted for 1d15h8m37s, wasted 8.06MB)
Web App Attack
๐บ๐ธ
octageeks.com
2026-01-02 05:06:14
(9 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฌ๐ง
[email protected]
2026-01-02 01:03:26
(9 months ago)
...
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-01-01 23:01:43
(9 months ago)
Auto-ban: >3000 req/min op 2026-01-01
Hacking
Web App Attack
SSH
Anonymous
2026-01-01 16:30:52
(9 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ฟ
mirasayon
2026-01-01 15:12:00
(9 months ago)
Port Scan
Bad Web Bot
๐ซ๐ฎ
Jordy
2026-01-01 14:37:35
(9 months ago)
01/Jan/2026:15:37:38.143141 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
01/Jan/2026:15:37:38.143141 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 44.202.112.15] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "office.vetspons.nl"] [uri "/.git/config"] [unique_id "aVaGspf7KlZ9mGYynadLIwAAAAA"]
01/Jan/2026:15:37:38.143141 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 44.202.112.15] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME
...
show less
Web App Attack
๐ซ๐ฎ
Jordy
2026-01-01 09:57:51
(9 months ago)
01/Jan/2026:10:57:53.916473 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client ...
show more
01/Jan/2026:10:57:53.916473 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 44.202.112.15] ModSecurity: Warning. String match within "/accept-charset/ /content-encoding/ /proxy/ /lock-token/ /content-range/ /if/" at TX:header_name_accept-charset. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "1128"] [id "920450"] [msg "HTTP header is restricted by policy (/accept-charset/)"] [data "Restricted header detected: /accept-charset/"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/12.1"] [hostname "im.vetspons.nl"] [uri "/.git/config"] [unique_id "aVZFIYnq02WU6voOHEgQEwAAAAQ"]
01/Jan/2026:10:57:53.916473 +0100Apache-Error: [file "apache2_util.c"] [line 275] [level 3] [client 44.202.112.15] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [f
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 09:44:48
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 04:44:41.584524 2026] [security2:error] [pid 17277:tid 17277] [client 44.202.112.15:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totalsafe-security.com"] [uri "/.git/config"] [unique_id "aVZCCYQ8URwouXKoJKOQ3AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 09:11:08
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 04:11:00.489455 2026] [security2:error] [pid 21614:tid 21614] [client 44.202.112.15:35402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "htaautosales.com"] [uri "/.git/config"] [unique_id "aVY6JDfzvjqzylJbmwTodgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 08:16:14
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 03:16:08.663274 2026] [security2:error] [pid 32534:tid 32534] [client 44.202.112.15:45428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.yaseminelhan.com.kircali.net"] [uri "/.git/config"] [unique_id "aVYtSCC8MNb1edG1EUXEjQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 07:51:18
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 44.202.112.15 (ec2-44-202-112-15.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 01 02:51:12.593551 2026] [security2:error] [pid 8228:tid 8228] [client 44.202.112.15:54668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosacid.com"] [uri "/.git/config"] [unique_id "aVYncLs_eYxc2NyOEOITswAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack