π·π΄
iulianh
2026-10-01 16:07:22
(34 minutes ago)
80,443
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-10-01 15:58:36
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:58:32.368484 2026] [security2:error] [pid 15309:tid 15309] [client 137.184.209.239:53246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sawmat.com"] [uri "/.git/config"] [unique_id "ar6DKG8OW3rxBrRzC42_MgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©π°
toolbit.online
2026-10-01 15:30:02
(1 hour ago)
Automated scan for common CMS/admin/secrets-exposure paths (WordPress/Joomla/phpMyAdmin/.env/.git/cg ...
show more
Automated scan for common CMS/admin/secrets-exposure paths (WordPress/Joomla/phpMyAdmin/.env/.git/cgi-bin and similar) that do not exist on this server - all requests 404'd, volume stayed below any automatic ban threshold.
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:10:54
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:10:49.874846 2026] [security2:error] [pid 19763:tid 19763] [client 137.184.209.239:59376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "samuelpaley.com"] [uri "/.git/config"] [unique_id "ar5b2fu6hMW6wWUvuwmTfwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-01 12:52:19
(3 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:20:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:20:14.744755 2026] [security2:error] [pid 31871:tid 31871] [client 137.184.209.239:59860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dockrockukiah.com"] [uri "/.git/config"] [unique_id "ar5P_rh9yxso24devPPqhgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:06:08
(4 hours ago)
[ns3.backorder.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 11:20:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:20:04.019611 2026] [security2:error] [pid 6197:tid 6197] [client 137.184.209.239:60640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web142.dnchosting.com"] [uri "/.git/config"] [unique_id "ar5B5EfDcKEtRwJo8Sn4FAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-01 10:44:05
(5 hours ago)
[01/Oct/2026:13:44:04 +0300] -- 137.184.209.239 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.g ...
show more
[01/Oct/2026:13:44:04 +0300] -- 137.184.209.239 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 10:30:05
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:29:58.059593 2026] [security2:error] [pid 10062:tid 10062] [client 137.184.209.239:59018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pistone.us"] [uri "/.git/config"] [unique_id "ar42JpXfyD5Q0xcfWndImgAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 09:34:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:34:34.013677 2026] [security2:error] [pid 11081:tid 11081] [client 137.184.209.239:57456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jolankagroup.com"] [uri "/.git/config"] [unique_id "ar4pKtJqDyuHubgqapLiGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-01 09:23:54
(7 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 137.184.209.239 - - [01/Oct/2026:11:23:46 +0200] "GET /.git/config HTTP/1.1" 403 519 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-10-01 09:05:17
(7 hours ago)
Abuse Detected (10)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 08:54:34
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 137.184.209.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:54:31.281062 2026] [security2:error] [pid 8466:tid 8466] [client 137.184.209.239:55794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "purlandpurr.com"] [uri "/.git/config"] [unique_id "ar4fxwxQS24uqO8_yI6KDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-10-01 08:42:33
(7 hours ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack