๐ซ๐ท
Little Iguana
2026-09-12 08:35:58
(5 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ซ๐ท
Little Iguana
2026-09-10 19:59:11
(6 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
Anonymous
2026-09-10 05:10:23
(1 week ago)
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /opt/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (M ...
show more
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /opt/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /laravel/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /symfony/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /wordpress/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
104.23.160.136 - - [10/Sep/2026:07:10:21 +0200] "GET /wp/.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like G
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-08 10:44:12
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:57:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:56:59.382517 2026] [security2:error] [pid 1043:tid 1043] [client 104.23.160.136:10270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.spiritofacorn.com"] [uri "/.git/HEAD"] [unique_id "apCkmxG7JWnkwNhOjIACVAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:21:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:21:47.635712 2026] [security2:error] [pid 3661:tid 3661] [client 104.23.160.136:10938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wgs.cc"] [uri "/.git/HEAD"] [unique_id "apCcW-yZp1_bWlKx7inv_wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ISPLtd
2026-08-27 17:40:17
(2 weeks ago)
104.23.160.136 [27/Aug/2026:14:40:17 -0300] victaxes.com:443 URL:/.git/HEAD "GET /.git/HEAD
104.23.1 ...
show more
104.23.160.136 [27/Aug/2026:14:40:17 -0300] victaxes.com:443 URL:/.git/HEAD "GET /.git/HEAD
104.23.160.136 [27/Aug/2026:14:40:17 -0300] victaxes.com:443 URL:/.git/config "GET /.git/config
...
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 15:09:57
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
Actors.Bible
2026-08-27 13:57:42
(3 weeks ago)
Webapp Vulnerability Probing:
GET /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:53:41
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:53:37.584779 2026] [security2:error] [pid 12404:tid 12425] [client 104.23.160.136:9601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nextlevelpsych.com"] [uri "/.git/HEAD"] [unique_id "apBBYUMxlDLTqmmkGpytJgAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:27:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:27:19.184909 2026] [security2:error] [pid 25427:tid 25427] [client 104.23.160.136:9485] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.garantaconsulting.com"] [uri "/.git/config"] [unique_id "apAtJ8YBBxT9OnC_roA7AQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-27 07:57:30
(3 weeks ago)
104.23.160.136 - - [27/Aug/2026:01:57:30 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5. ...
show more
104.23.160.136 - - [27/Aug/2026:01:57:30 -0600] "GET /.git/config HTTP/2.0" 300 4342 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ง๐ช
madeit
2026-08-27 04:49:10
(3 weeks ago)
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-27 04:09:18
(3 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-26 23:45:11
(3 weeks ago)
-:443 104.23.160.136 - - [27/Aug/2026:01:45:09 +0200] - "GET /.git/config HTTP/2.0" 404 2643 "-" "Mo ...
show more
-:443 104.23.160.136 - - [27/Aug/2026:01:45:09 +0200] - "GET /.git/config HTTP/2.0" 404 2643 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Bad Web Bot