๐ณ๐ฑ
homeshowdomain.nl
2026-08-23 22:00:25
(4 hours ago)
Auto-ban: >3000 req/min op 2026-08-23
Web App Attack
SSH
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-08-23 21:03:41
(5 hours ago)
[Mon Aug 24 07:03:41.011107 2026] [security2:error] [pid 26935] [client 170.64.166.157:42572] [clien ...
show more
[Mon Aug 24 07:03:41.011107 2026] [security2:error] [pid 26935] [client 170.64.166.157:42572] [client 170.64.166.157] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.git/config"] [unique_id "aotgLaE_1pRWLwm9eFEtrQAAAAw"]
...
show less
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-08-23 20:01:21
(6 hours ago)
170.64.166.157 - - [24/Aug/2026:01:31:20 +0530] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 ...
show more
170.64.166.157 - - [24/Aug/2026:01:31:20 +0530] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-23 15:58:35
(10 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-08-23 14:57:28
(11 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:59:02
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:58:58.241394 2026] [security2:error] [pid 19155:tid 19155] [client 170.64.166.157:57106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portalvasco.com"] [uri "/.git/config"] [unique_id "aorukmxsurzJ7vr1v1EEpgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:12:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:12:26.355108 2026] [security2:error] [pid 14634:tid 14634] [client 170.64.166.157:58948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "safeharbourfund.com"] [uri "/.git/config"] [unique_id "aorVmuK4bdBIYf0wotCX5gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 10:44:58
(15 hours ago)
PSCSERV WPSCAN 170.64.166.157
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:35:50
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.166.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:35:45.467913 2026] [security2:error] [pid 7954:tid 7954] [client 170.64.166.157:49816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mountainjaytherapy.com"] [uri "/.git/config"] [unique_id "aorNAfVBuKY9llw-Rqg89gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-23 10:33:34
(15 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-crit.
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-08-23 10:06:50
(16 hours ago)
Brute force
Brute-Force
Anonymous
2026-08-23 09:30:02
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ญ๐ณ
unph
2026-08-23 09:23:36
(16 hours ago)
Intento de acceso sospechoso bloqueado por AbuseIPDB Blocker Plugin
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-08-23 09:20:08
(16 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-23 09:13:16
(16 hours ago)
170.64.166.157 - - [23/Aug/2026:08:26:11 +0200] "GET /.git/config HTTP/1.1" 301 588 "-" "Mozilla/5.0 ...
show more
170.64.166.157 - - [23/Aug/2026:08:26:11 +0200] "GET /.git/config HTTP/1.1" 301 588 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.166.157 - - [23/Aug/2026:08:26:13 +0200] "GET /.git/config HTTP/1.1" 403 4490 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.166.157 - - [23/Aug/2026:11:13:13 +0200] "GET /.git/config HTTP/1.1" 301 588 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Web App Attack
Hacking