🇩🇪
dinginess6354
2026-09-07 06:38:06
(5 days ago)
Unauthorized Access Attempt
Port Scan
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-06 04:33:36
(6 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /dump.tar.gz | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:53:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:53:23.075651 2026] [security2:error] [pid 5035:tid 5035] [client 130.211.97.167:42424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ergo84.com"] [uri "/htdocs/.git/config"] [unique_id "apydY1y43Z79Ve2ppTo40AAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:07:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:07:06.781263 2026] [security2:error] [pid 16283:tid 16283] [client 130.211.97.167:35012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.iainrealtor.com"] [uri "/app/.git/config"] [unique_id "apyEeob-YBGnjh8PRa5ghgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:01:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:00:57.099160 2026] [security2:error] [pid 22185:tid 22185] [client 130.211.97.167:51218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janaia.com"] [uri "/public/.git/config"] [unique_id "apt32UUUEnmxKznxN2kmYwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:35
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:54:13
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:54:07.324410 2026] [security2:error] [pid 14261:tid 14261] [client 130.211.97.167:37200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ezsmiledental.com"] [uri "/var/www/.git/config"] [unique_id "aps9_9a2Txz3SXWoEN5FvgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:37:29
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
paissangroup
2026-09-04 20:17:03
(1 week ago)
Multiple WAF Violations
Web App Attack
🇩🇪
webanyone
2026-09-04 19:02:30
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:56:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:56:29.863574 2026] [security2:error] [pid 18968:tid 18968] [client 130.211.97.167:43202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.eaglespiritproductions.com"] [uri "/.git/config"] [unique_id "apqx7d_1ZpbagjEd8UWtgAAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 09:57:35
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
🇷🇺
olegio
2026-09-04 08:24:44
(1 week ago)
130.211.97.167 - - [04/Sep/2026:08:24:44 +0000] "GET /var/www/.git/config HTTP/1.1" 404 146 "-" "cru ...
show more
130.211.97.167 - - [04/Sep/2026:08:24:44 +0000] "GET /var/www/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
130.211.97.167 - - [04/Sep/2026:08:24:44 +0000] "GET /public/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:20:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:20:49.065731 2026] [security2:error] [pid 908:tid 908] [client 130.211.97.167:39676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kraftre.com"] [uri "/backend/.git/config"] [unique_id "appjQQ7fFaUdu8y04aHXcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:01:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 130.211.97.167 (167.97.211.130.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:01:02.537522 2026] [security2:error] [pid 5271:tid 5271] [client 130.211.97.167:37490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.adonamusic.com"] [uri "/src/.git/config"] [unique_id "appenoc4OVx3g-gdPh2ApQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack