๐ฉ๐ช
FeG Deutschland
2026-09-01 16:59:55
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
retrokitty.net
2026-08-30 05:29:32
(3 days ago)
172.71.131.135 - - [30/Aug/2026:05:29:30 +0000] "GET /.git/config HTTP/2.0" 503 19141 "-" "Mozilla/5 ...
show more
172.71.131.135 - - [30/Aug/2026:05:29:30 +0000] "GET /.git/config HTTP/2.0" 503 19141 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 16:03:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:03:31.979235 2026] [security2:error] [pid 27095:tid 27095] [client 172.71.131.135:12272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ezekielproductions.com"] [uri "/.git/HEAD"] [unique_id "apMC00GzvrbTw8AURkCq0wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-29 05:35:47
(4 days ago)
Web App Attack
๐ฉ๐ช
kkw
2026-08-28 21:09:57
(5 days ago)
muminoslaw.psifactor.pl:443 172.71.131.135 - - [28/Aug/2026:23:09:57 +0200] "GET /.git/HEAD HTTP/2.0 ...
show more
muminoslaw.psifactor.pl:443 172.71.131.135 - - [28/Aug/2026:23:09:57 +0200] "GET /.git/HEAD HTTP/2.0" 404 421 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
SSH
๐ซ๐ท
Little Iguana
2026-08-28 13:16:12
(5 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-28 05:45:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:45:37.786365 2026] [security2:error] [pid 17604:tid 17604] [client 172.71.131.135:9568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thomaschemical.net"] [uri "/.git/HEAD"] [unique_id "apEggRxvPAIIC7onIk8lrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:09:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:09:04.168674 2026] [security2:error] [pid 3907823:tid 3907904] [client 172.71.131.135:12993] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ceresfund.com"] [uri "/.git/config"] [unique_id "apDRoG8AqE5mwNkTF50KIwAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
micropedro
2026-08-27 23:21:07
(6 days ago)
8 incidents: web scanning/attack. First: 2026-08-27 19:20, Last: 2026-08-27 19:21 UTC. Triggers: fir ...
show more
8 incidents: web scanning/attack. First: 2026-08-27 19:20, Last: 2026-08-27 19:21 UTC. Triggers: firewall-http.
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:33:32
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:33:28.249371 2026] [security2:error] [pid 3304:tid 3304] [client 172.71.131.135:12728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zpepg.xyz.justmakingitbetter.com"] [uri "/.git/config"] [unique_id "apC7OGFElKxJsfPnmSGS0QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 19:32:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:32:01.846098 2026] [security2:error] [pid 18849:tid 18849] [client 172.71.131.135:13325] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.toxicwater.com"] [uri "/.git/config"] [unique_id "ao8_MRLWMJ_4-35mr3K4ywAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 21:59:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 17:59:15.063768 2026] [security2:error] [pid 14070:tid 14070] [client 172.71.131.135:13814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.paulpasquali.com"] [uri "/.git/HEAD"] [unique_id "ao4QM1AIklTz2OwdIxEv1gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 22:43:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 18:43:24.120740 2026] [security2:error] [pid 23506:tid 23506] [client 172.71.131.135:11768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.campbellsclan.com"] [uri "/.git/HEAD"] [unique_id "aozJDCGyhm0zHRaS2uiNZgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 15:16:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:16:11.513492 2026] [security2:error] [pid 17799:tid 17799] [client 172.71.131.135:11743] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.virginiabeachlovebird.com"] [uri "/.git/HEAD"] [unique_id "aosOu88HTy6AmoWsKcQrFwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:18:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.131.135 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:18:09.546965 2026] [security2:error] [pid 17061:tid 17061] [client 172.71.131.135:12014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.shieldsenterprises.com"] [uri "/.git/HEAD"] [unique_id "aorW8fMBtMGlVM6IFdW4SQAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack