π¦πΊ
Klaverstyn
2026-09-15 13:46:16
(16 hours ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
π¦πΊ
A.i.D.A.N.N
2026-09-15 13:45:22
(16 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
π¦πΊ
FEWA
2026-09-15 13:26:47
(16 hours ago)
Fail2Ban Ban Triggered
Hacking
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-15 13:14:17
(16 hours ago)
[Tue Sep 15 23:14:16.559616 2026] [security2:error] [pid 242708] [client 134.209.127.190:35372] [cli ...
show more
[Tue Sep 15 23:14:16.559616 2026] [security2:error] [pid 242708] [client 134.209.127.190:35372] [client 134.209.127.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.git/config"] [unique_id "aqlEqDMli4Sehq35cC2OPwAAAAA"]
...
show less
Web App Attack
π¦πΊ
Klaverstyn
2026-09-15 12:47:25
(17 hours ago)
Repeated 403 Forbidden responses
Web App Attack
π¦πΊ
Bay13
2026-09-15 12:44:11
(17 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-15 12:41:36
(17 hours ago)
[Tue Sep 15 22:41:35.396979 2026] [security2:error] [pid 237337] [client 134.209.127.190:49192] [cli ...
show more
[Tue Sep 15 22:41:35.396979 2026] [security2:error] [pid 237337] [client 134.209.127.190:49192] [client 134.209.127.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "aqk8_6TBjSbSVsNED52jCwAAAAM"]
...
show less
Web App Attack
π¦πΊ
paulshipley.com.au
2026-09-15 12:22:04
(17 hours ago)
[Tue Sep 15 22:22:02.962518 2026] [security2:error] [pid 220922] [client 134.209.127.190:42588] [cli ...
show more
[Tue Sep 15 22:22:02.962518 2026] [security2:error] [pid 220922] [client 134.209.127.190:42588] [client 134.209.127.190] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/.git/config"] [unique_id "aqk4anJryDq9ZsW8LRMELAAAAAg"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 12:18:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 134.209.127.190 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 134.209.127.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:18:44.612240 2026] [security2:error] [pid 31645:tid 31645] [client 134.209.127.190:34128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.rohanbyles.com.au"] [uri "/.git/config"] [unique_id "aqk3pML5TqpWOkvuUGDchwAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-09-15 12:04:45
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π¦πΊ
afleventoffice.com.au
2026-09-15 02:17:00
(1 day ago)
GET /.git/config HTTP/1.1
Web App Attack
πΊπΈ
zcampbell
2026-09-14 20:48:46
(1 day ago)
Web vulnerability scanning: probing for exposed sensitive files (.git). Detected and blocked automat ...
show more
Web vulnerability scanning: probing for exposed sensitive files (.git). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
πΊπΈ
IndigoRidge
2026-09-14 17:46:19
(1 day ago)
Knock-Knock HTTP honeypot activity; time=2026-09-14 17:28:28; http_method=GET; http_path=/.git/confi ...
show more
Knock-Knock HTTP honeypot activity; time=2026-09-14 17:28:28; http_method=GET; http_path=/.git/config; http_purpose=config_exposure; http_exploit=Git Metadata Exposure; http_user_agent=Opera/9.80 (Windows NT 5.2; U; en) Presto/2.2.15 Version/10.10
show less
Web App Attack
πΊπΈ
IndigoRidge
2026-09-14 17:28:28
(1 day ago)
134.209.127.190 - - [14/Sep/2026:13:28:26 -0400] "GET /.git/config HTTP/1.1" 404 3011 "-" "Opera/9.6 ...
show more
134.209.127.190 - - [14/Sep/2026:13:28:26 -0400] "GET /.git/config HTTP/1.1" 404 3011 "-" "Opera/9.60 (J2ME/MIDP; Opera Mini/4.1.11320/608; U; en) Presto/2.2.0"
134.209.127.190 - - [14/Sep/2026:13:28:26 -0400] "GET /.git/config HTTP/1.1" 404 5704 "-" "Mozilla/5.0 (Windows NT 5.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/49.0.2623.112 Safari/537.36"
134.209.127.190 - - [14/Sep/2026:13:28:28 -0400] "GET /.git/config HTTP/1.1" 503 2456 "-" "Opera/9.25 (Windows NT 6.0; U; en)"
...
show less
Web App Attack
πΊπΈ
xmission.com
2026-09-14 13:58:21
(1 day ago)
Blocked by UFW (TCP on 443)
Source port: 38012
TTL: 50
Packet length: 60
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 443)
Source port: 38012
TTL: 50
Packet length: 60
TOS: 0x08
This report (for 134.209.127.190) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack