๐ซ๐ท
vtchost.com
2026-09-16 21:05:32
(5 days ago)
known bad web user agent
...
Bad Web Bot
๐ธ๐ช
OnTheEdge
2026-09-03 13:34:28
(2 weeks ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐ฌ๐ง
PeravixGroup
2026-06-09 19:31:10
(3 months ago)
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity ...
show more
Honeypot detection: Apache CouchDB unauthorized access / exploitation attempt on port 5984. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ฆ๐บ
RedBear IT
2026-03-26 10:00:37
(5 months ago)
"DDoS against public endpoint"
DDoS Attack
๐ฑ๐ป
garmtech.com
2026-02-20 10:29:02
(7 months ago)
IM360 WAF: Attempt to upload malware
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-09 21:10:26
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 16:10:05.073447 2026] [security2:error] [pid 8229:tid 8229] [client 104.207.32.125:39311] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gapanda.com"] [uri "/admin/.env"] [unique_id "aYpNLdNIhhrjiv300FeojgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 16:45:34
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 11:45:30.920234 2026] [security2:error] [pid 22227:tid 22227] [client 104.207.32.125:34323] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fuentevictoria.com"] [uri "/v2/.git/config"] [unique_id "aYoPKhAsEmKpPN6aLDo1rwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 16:28:25
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 11:28:21.534199 2026] [security2:error] [pid 1163329:tid 1163329] [client 104.207.32.125:31155] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftiptondds.com"] [uri "/v2/.git/config"] [unique_id "aYoLJbb1vHBvjl6byUSnjgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 12:41:32
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 07:41:23.242612 2026] [security2:error] [pid 15712:tid 15712] [client 104.207.32.125:39587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamepart.com"] [uri "/site/.git/config"] [unique_id "aYnV8-NpGmUZJJE3rg4LagAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-09 05:23:49
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.32.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 09 00:23:39.659926 2026] [security2:error] [pid 4009:tid 4009] [client 104.207.32.125:34491] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundingworkingcapital.com"] [uri "/site/.git/config"] [unique_id "aYlvW9k5bmcFqdsf3SDyrgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-02-09 01:58:32
(7 months ago)
GET /backup/.git/config HTTP/1.1
Web App Attack
๐ฉ๐ช
LRob
2026-01-05 01:50:33
(8 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2025-12-29 14:01:09
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฑ๐ป
garmtech.com
2025-12-26 05:55:39
(8 months ago)
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing ...
show more
Attempted access to sensitive endpoint (/.git/HEAD) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐ฉ๐ช
iNetWorker
2025-12-26 03:30:50
(8 months ago)
trolling for resource vulnerabilities
Web App Attack