๐ณ๐ฑ
jjnxpct
2025-10-04 03:45:07
(10 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 210492)
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-03 17:41:48
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 13:41:43.372461 2025] [security2:error] [pid 18321:tid 18321] [client 13.217.32.250:52562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yuichiro.us"] [uri "/.git/config"] [unique_id "aOAK1-HyAAXLn3snQ3Q6aQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-03 17:41:42
(10 months ago)
13.217.32.250 - - [03/Oct/2025:19:41:42 +0200] "GET /.git/config HTTP/1.1" 403 4945 "-" "Mozilla/5.0 ...
show more
13.217.32.250 - - [03/Oct/2025:19:41:42 +0200] "GET /.git/config HTTP/1.1" 403 4945 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15G77 MicroMessenger/7.0.3(0x17000321) NetType/WIFI Language/zh_CN"
...
show less
Web App Attack
๐ฉ๐ช
DocNetzwerk
2025-10-03 17:34:44
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 13.217.32.250 (US/United States/ec2-13- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 13.217.32.250 (US/United States/ec2-13-217-32-250.compute-1.amazonaws.com)
show less
SQL Injection
๐ฉ๐ช
grassau.com
2025-10-03 17:12:02
(10 months ago)
(mod_security) mod_security triggered on hostname [redacted] 13.217.32.250 (US/United States/ec2-13- ...
show more
(mod_security) mod_security triggered on hostname [redacted] 13.217.32.250 (US/United States/ec2-13-217-32-250.compute-1.amazonaws.com)
show less
SQL Injection
๐บ๐ธ
mnsf
2025-10-03 17:05:07
(10 months ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2025-10-03 17:03:06
(10 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-03 16:53:47
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 12:53:41.517999 2025] [security2:error] [pid 25388:tid 25388] [client 13.217.32.250:43328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web197.dnchosting.com"] [uri "/.git/config"] [unique_id "aN__ldR8JmQ9hQ1ckPcKHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2025-10-03 16:49:05
(10 months ago)
Probing for non-installed web apps or current vulnerabilities.
Hacking
Web App Attack
Anonymous
2025-10-03 16:40:41
(10 months ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ฉ๐ช
Kreapptivo
2025-10-03 16:40:20
(10 months ago)
[03/Oct/2025:18:40:18 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (X11; Fedora; ...
show more
[03/Oct/2025:18:40:18 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2025-10-03 16:32:04
(10 months ago)
Failed login attempt detected by Fail2Ban in recidive jail
Brute-Force
๐ซ๐ท
tr1n
2025-10-03 16:28:03
(10 months ago)
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET ...
show more
Triggered Cloudflare WAF (botFight) from US.
Action taken: MANAGED_CHALLENGE
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Maxthon/4.4.6.1000 Chrome/30.0.1599.101 Safari/537.36
show less
Bad Web Bot
๐ง๐ช
cmbplf
2025-10-03 16:28:01
(10 months ago)
2.918 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-10-03 16:27:59
(10 months ago)
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amaz ...
show more
(mod_security) mod_security (id:210492) triggered by 13.217.32.250 (ec2-13-217-32-250.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 12:27:54.674465 2025] [security2:error] [pid 2976:tid 2976] [client 13.217.32.250:40552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stgeorgellc.com"] [uri "/.git/config"] [unique_id "aN_5inOG2T7qUzRz-AtR_gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack