🇮🇳
evicky2002
2026-09-14 06:00:01
(2 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇲🇽
octageeks.com
2026-09-14 04:13:04
(4 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-13 22:16:31
(10 hours ago)
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-13 21:59:20
(10 hours ago)
Auto-ban: >3000 req/min op 2026-09-13
Web App Attack
SSH
Hacking
🇩🇪
todix
2026-09-13 16:48:08
(15 hours ago)
Web App Attack Exploid from 172.86.81.63
Web App Attack
🇬🇧
blik2108
2026-09-13 16:40:33
(15 hours ago)
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/credentials- ...
show more
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/credentials-helper HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/config HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/packed-refs HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/config.credentials HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/refs/remotes/origin/master HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.uk:443 172.86.81.63 - - [13/Sep/2026:17:40:21 +0100] "GET /.git/logs/refs/heads/main HTTP/1.1" 404 5355 "-" "Mozilla/5.0 (X11; Linux x86_64)"
blog.blacknellsatsea.co.u
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 16:38:37
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.81.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.81.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:38:31.955451 2026] [security2:error] [pid 31953:tid 31953] [client 172.86.81.63:58096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blockdredge.com"] [uri "/.git/logs/HEAD"] [unique_id "aqbRh1l3Xf0sTkM7v9MN_wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
blinx
2026-09-13 16:37:33
(16 hours ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
🇺🇦
Olexiy Backend
2026-09-13 16:26:09
(16 hours ago)
172.86.81.63
...
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-13 16:16:36
(16 hours ago)
[REDACTED] 172.86.81.63 - - [13/Sep/2026:18:16:36 +0200] "GET /.git/packed-refs HTTP/1.1" 404 4498 " ...
show more
[REDACTED] 172.86.81.63 - - [13/Sep/2026:18:16:36 +0200] "GET /.git/packed-refs HTTP/1.1" 404 4498 "-" "Mozilla/5.0 (X11; Linux x86_64)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-13 16:16:23
(16 hours ago)
2026/09/13 16:16:22 [error] 1442485#1442485: *8186519 access forbidden by rule, client: 172.86.81.63 ...
show more
2026/09/13 16:16:22 [error] 1442485#1442485: *8186519 access forbidden by rule, client: 172.86.81.63, server: binixo.es, request: "GET /.git/refs/heads/master HTTP/1.1", host: "binixo.es"
2026/09/13 16:16:22 [error] 1442485#1442485: *8186520 access forbidden by rule, client: 172.86.81.63, server: binixo.es, request: "GET /.git/info/exclude HTTP/1.1", host: "binixo.es"
2026/09/13 16:16:22 [error] 1442489#1442489: *8186521 access forbidden by rule, client: 172.86.81.63, server: binixo.es, request: "GET /.git.bak HTTP/1.1", host: "binixo.es"
...
show less
Web App Attack
🇷🇴
iulianh
2026-09-13 15:48:56
(16 hours ago)
80,443
Brute-Force
SSH
🇳🇱
debestelapp
2026-09-13 15:40:12
(16 hours ago)
Web App Attack
🇨🇦
Anytech
2026-09-13 15:32:49
(17 hours ago)
Blocked by ConnMonitor
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:28:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.81.63 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.81.63 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:28:33.485616 2026] [security2:error] [pid 20540:tid 20540] [client 172.86.81.63:37038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beetreelabs.com"] [uri "/.git/refs/heads/master"] [unique_id "aqbBIazsrxIFFzsEfWLWlAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack