Anonymous
2026-09-03 07:37:02
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:35:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:35:08.559944 2026] [security2:error] [pid 26773:tid 26773] [client 176.57.188.63:43424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.surveyiowa.com"] [uri "/.git/config"] [unique_id "apkHDAll5bDO-5rfjI3sUQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:13:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:13:54.187345 2026] [security2:error] [pid 16153:tid 16153] [client 176.57.188.63:43706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.orcastrong.com"] [uri "/.git/config"] [unique_id "apkCEvrtd0HTHlHE1NbMUAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-03 04:55:43
(7 hours ago)
[ThuSep0306:55:40.4419912026][security2:error][pid2425803:tid2425893][client176.57.188.63:0]ModSecur ...
show more
[ThuSep0306:55:40.4419912026][security2:error][pid2425803:tid2425893][client176.57.188.63:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"autodiscover.maurokorangraf.ch\"][uri\"/.git/config\"][unique_id\"apj9zMbulsJBNr1GW85KfgAAAdY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 04:47:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:47:29.377997 2026] [security2:error] [pid 27226:tid 27226] [client 176.57.188.63:47058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lyldevelopers.com"] [uri "/.git/config"] [unique_id "apj74URqgGN3Qex_-QYWoAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 04:30:07
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:30:02.594212 2026] [security2:error] [pid 22941:tid 22941] [client 176.57.188.63:53636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.golflavahotsprings.com"] [uri "/.git/config"] [unique_id "apj3yn8t0YzF5WcoOY8c5AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-03 04:23:43
(7 hours ago)
csagent: score 19.5: secrets grab x2; 1 domain(s) in 8s
Web App Attack
🇵🇱
Budyn
2026-09-03 04:17:08
(8 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: grafana.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 01:25:03
(10 hours ago)
suspicious request in access.log
Web App Attack
🇬🇧
consul.to
2026-09-03 00:25:41
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 00:10:42
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:949110) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 20:10:36.259464 2026] [security2:error] [pid 14741:tid 14741] [client 176.57.188.63:42282] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "autodiscover.boraborapearlbookings.com"] [uri "/.git/config"] [unique_id "api6_ND2qoi7j5_xvxsL6gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:50:06
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:49:55.869561 2026] [security2:error] [pid 12183:tid 12183] [client 176.57.188.63:49868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.abdulhameeds.art"] [uri "/.git/config"] [unique_id "api2IziDjFP2PJDEnHGowQAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-02 21:59:59
(14 hours ago)
Auto-ban: >3000 req/min op 2026-09-02
Web App Attack
SSH
Hacking
Anonymous
2026-09-02 21:18:15
(15 hours ago)
Scanner hitting /.git/config on ara-oman.com (CONTABO-04) — aaguard
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-02 20:09:58
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 176.57.188.63 (vipp.domainship.xyz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 16:09:50.833712 2026] [security2:error] [pid 25608:tid 25608] [client 176.57.188.63:52726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prostar.industries"] [uri "/wp-config.php.bak"] [unique_id "apiCjjsl2TPRR9pkg0AfBgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack