๐ฌ๐ง
PeravixGroup
2026-05-07 06:26:32
(1 month ago)
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Sever ...
show more
Honeypot detection: Docker daemon unauthorized access / container escape attempt on port 2375. Severity: MEDIUM. Aaran.cloud
show less
Hacking
Exploited Host
๐ณ๐ฑ
jjnxpct
2026-02-16 04:54:46
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /admin/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-02-15 12:50:08
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 12:48:26
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:48:22.467462 2026] [security2:error] [pid 14395:tid 14395] [client 104.207.49.222:44023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toddgoranson.com"] [uri "/wp/.git/config"] [unique_id "aZHAlmI2MSEe2Y0yoDJDCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-02-15 12:22:38
(4 months ago)
Try to access /app/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 12:06:20
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:06:17.208692 2026] [security2:error] [pid 1218510:tid 1218510] [client 104.207.49.222:38379] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techspertnet.com"] [uri "/backend/.env"] [unique_id "aZG2uX5cosi7oETGFTEeGQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 11:45:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 06:45:15.468711 2026] [security2:error] [pid 21711:tid 21711] [client 104.207.49.222:21877] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thoughtage.org"] [uri "/dev/.git/config"] [unique_id "aZGxy1Y412lkIin1_jlfxAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-15 04:48:38
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /backup/.git/config (Rule ID: 930130) - Restricted File Access Attempt
show less
Hacking
Web App Attack
๐ฎ๐น
alph44
2026-02-15 03:56:43
(4 months ago)
(mod_security) mod_security (id:949110) triggered by 104.207.49.222 (BR/Brazil/-): 5 in the last 360 ...
show more
(mod_security) mod_security (id:949110) triggered by 104.207.49.222 (BR/Brazil/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 02:53:10
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:53:05.849364 2026] [security2:error] [pid 11987:tid 11987] [client 104.207.49.222:13337] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nanchy.net"] [uri "/frontend/.env"] [unique_id "aZE1EVooq5CM2RVMIVqPvQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-02-15 02:31:20
(4 months ago)
104.207.49.222 - - [15/Feb/2026:03:31:19 +0100] "GET /api/.env HTTP/1.1" 301 525 "-" "Mozilla/5.0 (W ...
show more
104.207.49.222 - - [15/Feb/2026:03:31:19 +0100] "GET /api/.env HTTP/1.1" 301 525 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-15 01:00:37
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 20:00:32.582130 2026] [security2:error] [pid 14054:tid 14054] [client 104.207.49.222:36341] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mskimberleesspace.com"] [uri "/admin/.git/config"] [unique_id "aZEasHb6j-SmsOi7haCS_gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-02-15 00:19:31
(4 months ago)
Blocking for trying to access an exploit file: /.env
Hacking
๐บ๐ธ
TPI-Abuse
2026-02-15 00:00:12
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:00:02.718408 2026] [security2:error] [pid 18066:tid 18066] [client 104.207.49.222:34851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "longacre.biz"] [uri "/test/.git/config"] [unique_id "aZEMgim9IoeCc7Vawvfh1gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-14 23:25:18
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.207.49.222 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 18:25:08.820220 2026] [security2:error] [pid 818:tid 818] [client 104.207.49.222:50673] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liyatalton.com"] [uri "/new/.git/config"] [unique_id "aZEEVOtpRnb6r2OJwBIbcQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack