๐ซ๐ท
ingroscart.it
2026-10-02 07:58:16
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
Alt255
2026-10-02 07:55:07
(1 hour ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 134.199.160.115 - - [02/Oct/2026:09:54:56 +0200] "GET /.git/config HTTP/1.1" 301 605 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-02 07:45:12
(1 hour ago)
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebK ...
show more
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Hacking
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-02 07:21:23
(1 hour ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:46:35
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:46:27.243013 2026] [security2:error] [pid 26956:tid 26956] [client 134.199.160.115:58374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "representacionesthompson.com"] [uri "/.git/config"] [unique_id "ar83I-IArFKrg219n6DukAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 02:29:33
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:29:26.193647 2026] [security2:error] [pid 4585:tid 4585] [client 134.199.160.115:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shubil.com"] [uri "/.git/config"] [unique_id "ar8XBljDFKQAdEQ-Bwa-8QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:17:44
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:17:40.992285 2026] [security2:error] [pid 14912:tid 14912] [client 134.199.160.115:58978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "framestoria.com"] [uri "/.git/config"] [unique_id "ar8GNBx6ue2S3l0Ns0YgDwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 00:37:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:37:44.514064 2026] [security2:error] [pid 23132:tid 23166] [client 134.199.160.115:35242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geekshop.com"] [uri "/.git/config"] [unique_id "ar782AVGq_Ri0eoX9w6UaAAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
radardatelecom
2026-10-01 22:26:03
(10 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:15
(11 hours ago)
Auto-ban: >3000 req/min op 2026-10-01
Web App Attack
SSH
Hacking
๐ฉ๐ช
big-cloud.nl
2026-10-01 20:49:24
(12 hours ago)
Try to access /.git/config
Web App Attack
Anonymous
2026-10-01 20:33:02
(12 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 20:09:19
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 16:09:16.585821 2026] [security2:error] [pid 1423:tid 1423] [client 134.199.160.115:42258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "finishlineenterprisesllc.com"] [uri "/.git/config"] [unique_id "ar697PZKlOkH0sNPmLgejwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-10-01 18:08:00
(14 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:32:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.199.160.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:32:37.564115 2026] [security2:error] [pid 3488:tid 3488] [client 134.199.160.115:51206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sveum.net"] [uri "/.git/config"] [unique_id "ar6ZNcH88Q2BwmTuDsvC3gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack