πΊπΈ
TPI-Abuse
2026-08-26 16:22:27
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:22:20.589871 2026] [security2:error] [pid 19185:tid 19185] [client 52.161.82.97:60481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.223"] [uri "/.git/HEAD"] [unique_id "ao8SvJKptWFompx15xPrTAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
ALPHANET
2026-08-23 16:25:29
(1 week ago)
web exploits
Hacking
Exploited Host
Web App Attack
π³π±
Roderic
2026-08-23 16:13:53
(1 week ago)
(apache_scanners-2) Failed apache-scanners trigger with match [redacted])
Port Scan
πΊπΈ
HamSammich
2026-08-23 15:47:07
(1 week ago)
Automated sensor: 25 HTTP connection/probe attempts over the last 24h (latest 2026-08-23T15:47Z).
Brute-Force
Web App Attack
πΊπΈ
zcampbell
2026-08-23 15:27:08
(1 week ago)
Web vulnerability scanning: probing for exposed sensitive files (.git). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.git). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-23 15:15:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:15:49.449291 2026] [security2:error] [pid 13003:tid 13003] [client 52.161.82.97:38213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.48"] [uri "/.git/HEAD"] [unique_id "aosOpWnoEBbcBStJoTdFZAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-03 03:22:48
(4 weeks ago)
denied traffic to a non-approved destination port. destination port 2082.
Port Scan
π·πΈ
Scan
2026-06-14 00:33:32
(2 months ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
πΊπΈ
RAP
2026-06-13 23:52:04
(2 months ago)
2026-06-13 23:52:04 UTC Unauthorized activity to TCP port 8080. Web App
Port Scan
Web App Attack
πΊπΈ
sandra361
2026-06-13 23:51:44
(2 months ago)
Port scan detected: 15 attempts across 15 ports (2077,2082,2083,2086,2087,2095,3000,3001,443,80,8000 ...
show more
Port scan detected: 15 attempts across 15 ports (2077,2082,2083,2086,2087,2095,3000,3001,443,80,8000,8090,8443,8880,8888). | Evidence: GHOST_SCAN: IN=enp1s0 SRC=52.161.82.97 LEN=60 TOS=0x00 PREC=0x00 TTL=43 ID=15303 DF PROTO=TCP SPT=57479 DPT=8443 WINDOW=64240 RES=0x00 SYN URGP=0
show less
Port Scan
Anonymous
2026-06-02 08:52:34
(2 months ago)
automatically banned
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 08:38:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 04:38:14.245875 2026] [security2:error] [pid 23301:tid 23301] [client 52.161.82.97:49672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.198"] [uri "/.env.local"] [unique_id "ah6Wdoxpt3qFpLDfFkifewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
VXG-NET
2026-06-02 05:32:48
(3 months ago)
port=80, indicator_type=info-leak
Hacking
πΉπ·
Threat.live
2026-06-02 05:30:09
(3 months ago)
Suspicious Connection Attempts
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-02 05:01:36
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 52.161.82.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:01:30.895310 2026] [security2:error] [pid 16712:tid 16712] [client 52.161.82.97:49192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.184"] [uri "/.git/config"] [unique_id "ah5jqhNvsQid2RHBoS0ltwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack