๐ฟ๐ฆ
conure
2026-07-23 12:11:30
(9 hours ago)
csagent: score 19.7: secrets grab x2; 2 domain(s) in 4s
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-23 06:00:00
(15 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-07-23 04:31:54
(16 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
JPPO
2026-07-22 22:52:47
(22 hours ago)
5 hits : Port 443 : GET /.git or /.git/HEAD, /.git/config ... /.DS_store
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-22 21:59:34
(23 hours ago)
Auto-ban: >3000 req/min op 2026-07-22
Web App Attack
SSH
Hacking
๐ซ๐ท
mail.avx.gr
2026-07-22 19:40:59
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 136.119.125.240 - - [22/Jul/2026:22:40:59 +0300] ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 136.119.125.240 - - [22/Jul/2026:22:40:59 +0300] "GET /.git/config HTTP/1.1" 403 6276 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 19:39:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 15:38:56.676026 2026] [security2:error] [pid 14765:tid 14775] [client 136.119.125.240:56390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maroontribe.philacentric.com"] [uri "/.git/config"] [unique_id "amEcUDefFI1JDEXR6PQFNQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-07-22 19:37:24
(1 day ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-07-22T19:32:06Z [proxy]
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-22 19:35:28
(1 day ago)
Try to access /.git/config
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-22 19:33:58
(1 day ago)
cloudlinux2 fail2ban: 2026-07-22 21:30:49,868 fail2ban.actions [1589]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-22 21:30:49,868 fail2ban.actions [1589]: NOTICE [plesk-wordpress] Ban 134.112.56.84cloudlinux2 fail2ban: 2026-07-22 21:30:48,917 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 134.112.56.84 - 2026-07-22 21:30:47cloudlinux2 fail2ban: 2026-07-22 21:30:52,854 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 193.36.224.241 - 2026-07-22 21:30:52cloudlinux2 fail2ban: 2026-07-22 21:30:48,861 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 134.112.56.84 - 2026-07-22 21:30:47cloudlinux2 fail2ban: 2026-07-22 21:30:49,874 fail2ban.filter [1589]: INFO [recidive] Found 134.112.56.84 - 2026-07-22 21:30:49cloudlinux2 fail2ban: 2026-07-22 21:30:49,597 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 134.112.56.84 - 2026-07-22 21:30:47cloudlinux2 fail2ban: 2026-07-22 21:31:21,297 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 4.182.249.152 - 2026-07-22 21:31:19cloudlinux2 fail2ban: 2026-07-22 21:31:
show less
FTP Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-07-22 19:27:57
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
FreeMyIP
2026-07-22 19:23:04
(1 day ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 18:52:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 14:52:41.522314 2026] [security2:error] [pid 1485685:tid 1485690] [client 136.119.125.240:53388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.onixgironashop.com.webcraftestudio.com"] [uri "/.git/config"] [unique_id "amEReSrpDJ56wY5rfiYP9QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-22 18:38:00
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 18:33:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.119.125.240 (240.125.119.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 14:32:59.394914 2026] [security2:error] [pid 1496906:tid 1496906] [client 136.119.125.240:56800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exners.com"] [uri "/.git/config"] [unique_id "amEM2-Z5RgcZCAY5b3n4ZwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack