๐ฉ๐ช
FeG Deutschland
2026-08-28 14:42:43
(18 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 13:02:04
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 12:35:39
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:35:34.009709 2026] [security2:error] [pid 25274:tid 25274] [client 104.199.68.151:53822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dymesich.com"] [uri "/var/www/.git/config"] [unique_id "apGAlst44rt1GNZcb9jD4gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:00:42
(17 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐บ๐ธ
mnsf
2026-08-27 20:05:14
(18 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:20:36
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:20:21.372960 2026] [security2:error] [pid 4838:tid 4838] [client 104.199.68.151:37400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oxysulfur.com.mroxygen.org"] [uri "/src/.git/config"] [unique_id "apB_5YSdjvRZHf1DGdDLIgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 17:52:35
(21 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
DonAtari
2026-08-27 12:54:51
(1 day ago)
DShield firewall scan - TCP to port 8000
Brute-Force
SSH
๐ซ๐ฎ
paissangroup
2026-08-27 11:55:32
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:24:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:23:58.617178 2026] [security2:error] [pid 5737:tid 5737] [client 104.199.68.151:51688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deargrampy.net"] [uri "/src/.git/config"] [unique_id "apACLmkmS-STj4cNHE3b8QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-27 09:19:17
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
Hacking
Bad Web Bot
๐จ๐ญ
4server
2026-08-27 05:00:54
(1 day ago)
[ThuAug2707:00:46.8420452026][security2:error][pid3586297:tid3586758][client104.199.68.151:0]ModSecu ...
show more
[ThuAug2707:00:46.8420452026][security2:error][pid3586297:tid3586758][client104.199.68.151:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"server-privato.com\"][uri\"/src/.git/config\"][unique_id\"ao_Efr00rnF6rh4ZvDK-eQAAAYo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:52:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.68.151 (151.68.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:52:41.509197 2026] [security2:error] [pid 24246:tid 24246] [client 104.199.68.151:36180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whomakestherules.com"] [uri "/src/.git/config"] [unique_id "ao_Cmb7CR8Ad7p10M1Q0DwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-08-27 04:32:04
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ท
dynamix
2026-08-27 03:03:58
(1 day ago)
Multiple WAF Violations
Web App Attack