Anonymous
2026-08-28 04:34:46
(15 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
Anonymous
2026-08-27 23:06:29
(20 hours ago)
Trying to access config files
Web App Attack
π³π±
homeshowdomain.nl
2026-08-27 22:00:25
(21 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
πΉπ·
Lucius
2026-08-27 06:06:18
(1 day ago)
Yetkisiz eriΕim denemesi / brute-force tespit edildi - SOC
Port Scan
Brute-Force
π²π½
octageeks.com
2026-08-27 04:21:31
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 23:11:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:11:26.665456 2026] [security2:error] [pid 6613:tid 6613] [client 136.117.129.228:33964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aroilcontrolsystem.com"] [uri "/.git/config"] [unique_id "ao9yntmW6eoAKbBm8tJWpAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅πΎ
armandosaucedo.me
2026-08-26 22:55:51
(1 day ago)
Threat Intelligence via ARMTI, Web Attack: GET /.git/config
Web App Attack
π«π·
Jimbo67
2026-08-26 22:53:48
(1 day ago)
Cloudflare WAF: 1 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=0189 ...
show more
Cloudflare WAF: 1 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=0189a8c2c2ab4a60bc709bad14577d18 | URIs=/.git/config | confidence=0.82
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-26 22:48:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:48:40.831990 2026] [security2:error] [pid 22812:tid 22812] [client 136.117.129.228:39624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arkqp.kreweofhyatt.com"] [uri "/.git/config"] [unique_id "ao9tSCiV-WZt_gqGduMSAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wordpresshosting.solutions
2026-08-26 22:46:15
(1 day ago)
Web app vulnerability scanning detected. Evidence: 136.117.129.228 - - [26/Aug/2026:22:44:52 +0000] ...
show more
Web app vulnerability scanning detected. Evidence: 136.117.129.228 - - [26/Aug/2026:22:44:52 +0000] "GET /.git/config HTTP/1.1" 404 11332 "-" "-"
136.117.129.228 - - [26/Aug/2026:22:46:14 +0000] "GET /.git/config HTTP/1.1" 404 6226 "-" "-"
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-08-26 22:00:26
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-26
Web App Attack
SSH
Hacking
Anonymous
2026-08-26 21:39:37
(1 day ago)
136.117.129.228 arduino.ua [27/Aug/2026:00:39:36 +0300] "GET /.git/config HTTP/1.1" 403 146 "-" "-" ...
show more
136.117.129.228 arduino.ua [27/Aug/2026:00:39:36 +0300] "GET /.git/config HTTP/1.1" 403 146 "-" "-" 0.000 2369
...
show less
Hacking
Web App Attack
π¦πΊ
2000cn.com.au
2026-08-26 21:39:16
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π±πΊ
conseilgouz
2026-08-26 21:36:36
(1 day ago)
are-17 : Block hidden directories=>/.git/config(/)
Hacking
πΊπΈ
TPI-Abuse
2026-08-26 21:35:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.117.129.228 (228.129.117.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 17:35:32.638334 2026] [security2:error] [pid 25611:tid 25611] [client 136.117.129.228:51138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ardath.net"] [uri "/.git/config"] [unique_id "ao9cJIZYPytjNE5U0zpttwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack