๐บ๐ธ
TPI-Abuse
2026-08-25 18:50:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:50:13.474134 2026] [security2:error] [pid 17455:tid 17455] [client 137.184.194.177:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aslanhan.com"] [uri "/.git/config"] [unique_id "ao3j5XKyJpzYVlzlwWmPDQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-25 15:08:01
(5 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:45:48
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:45:39.869860 2026] [security2:error] [pid 13439:tid 13439] [client 137.184.194.177:60846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "axiomcommercial.com"] [uri "/.git/config"] [unique_id "ao2Oc8o25YP-0eT2Y8rvFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-25 12:30:14
(8 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked a ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ต๐ฑ
Budyn
2026-08-25 10:37:45
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.xyz | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-25 09:18:28
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:02:48
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:02:43.290317 2026] [security2:error] [pid 2877:tid 2877] [client 137.184.194.177:45234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jcbergapparel.com"] [uri "/.git/config"] [unique_id "ao1aM2FftLhgzLD3OIFC_QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 07:43:56
(13 hours ago)
cloudlinux2 fail2ban: 2026-08-25 09:39:16,569 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 09:39:16,569 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 137.184.194.177 - 2026-08-25 09:39:16cloudlinux2 fail2ban: 2026-08-25 09:39:13,855 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 137.184.194.177 - 2026-08-25 09:39:13cloudlinux2 fail2ban: 2026-08-25 09:39:16,330 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 162.241.253.195 - 2026-08-25 09:39:16cloudlinux2 fail2ban: 2026-08-25 09:39:56,098 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 45.132.115.223 - 2026-08-25 09:39:55cloudlinux2 fail2ban: 2026-08-25 09:39:52,244 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 45.132.115.223 - 2026-08-25 09:39:51cloudlinux2 fail2ban: 2026-08-25 09:41:33,388 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.28.16 - 2026-08-25 09:41:33cloudlinux2 fail2ban: 2026-08-25 09:41:31,427 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.84.136 - 2026-08-25 09:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:24:36
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:24:30.765850 2026] [security2:error] [pid 13341:tid 13341] [client 137.184.194.177:48714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daisydoesoap.com"] [uri "/.git/config"] [unique_id "ao1DLokqtd2VTnEa7XWyLgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Kitki30.com
2026-08-25 06:53:01
(14 hours ago)
HTTP Probing. Log: 137.184.194.177 - - [25/Aug/2026:06:52:59 +0000] "GET /.git/config HTTP/1.1" 301 ...
show more
HTTP Probing. Log: 137.184.194.177 - - [25/Aug/2026:06:52:59 +0000] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 05:14:31
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.194.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:14:27.291804 2026] [security2:error] [pid 17958:tid 17958] [client 137.184.194.177:47150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccureiti.com"] [uri "/.git/config"] [unique_id "ao0ks4rsCaNDB8gymAoIMQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-25 05:04:22
(16 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack