Anonymous
2026-09-05 18:06:32
(12 hours ago)
Trying to access config files
Web App Attack
Anonymous
2026-09-04 22:10:09
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Webs ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Webshell probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:17:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:17:17.206255 2026] [security2:error] [pid 6275:tid 6275] [client 178.128.231.0:35492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bgraph.com"] [uri "/.git/config"] [unique_id "apn__UGB8I3BgmQmicLNvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:47:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:47:05.092402 2026] [security2:error] [pid 2942:tid 2942] [client 178.128.231.0:40652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bgellis.com"] [uri "/.git/config"] [unique_id "apn46fk4uCSZO0knBHtQCQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Epimetheus
2026-09-03 22:40:06
(2 days ago)
Unauthorized access attempts:
[GET] //lib/filemanager/dialog.php
[GET] //assets/filemanager/dialog. ...
show more
Unauthorized access attempts:
[GET] //lib/filemanager/dialog.php
[GET] //assets/filemanager/dialog.php
[GET] //assets/plugins/filemanager/dialog.php
[GET] //admin/jquery-file-upload/server/php/
[GET] //resources/js/tinymce/plugins/filemanager/dialog.php
[GET] //asset_admin/assets/plugins/jquery-file-upload/server/php/
[GET] //asset/server/php/
[GET] //assets/plugins/kcfinder/upload.php
[GET] //jquery.filer/php/readme.txt
[GET] //assets/plugins/js/jquery-file-upload/server/php/
[GET] //filemanager/filemanager/dialog.php
[GET] //assets/admin/bower_components/jquery.filer/php/readme.txt
[GET] //cms/tinymce/filemanager/filemanager/dialog.php
[GET] //jquery-file-upload/server/php/
[GET] //phpformbuilder/plugins/filemanager/dialog.php
[GET] //file-manager/initialize
[GET] //js/jquery-file-upload/server/php/
[GET] //ckeditor/kcfinder/upload.php
[GET] //public/scripts/filemanager/dialog.php
[GET] /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KH
...(Truncated)
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:21:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:21:01.163659 2026] [security2:error] [pid 14184:tid 14184] [client 178.128.231.0:43738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bfpsamoa.com"] [uri "/.git/config"] [unique_id "apnyze_mGsMYS7flfiZYhAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 22:10:01
(2 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-03 22:02:47
(2 days ago)
Trying to access config files
Web App Attack
Anonymous
2026-09-03 21:42:57
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-03 21:14:39
(2 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Webs ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: CA, Attack patterns: Webshell probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-03 20:40:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 20:14:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 178.128.231.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:13:59.721678 2026] [security2:error] [pid 9464:tid 9464] [client 178.128.231.0:34192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "betweentwotearsandshit.com"] [uri "/.git/config"] [unique_id "apnVB0LADAPxwpv7Kc6p4gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 19:25:10
(2 days ago)
178.128.231.0 - - [03/Sep/2026:21:25:09 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 ...
show more
178.128.231.0 - - [03/Sep/2026:21:25:09 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
178.128.231.0 - - [03/Sep/2026:21:25:09 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
178.128.231.0 - - [03/Sep/2026:21:25:10 +0200] "GET //vendor/laravel-filemanager/js/script.js HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
178.128.231.0 - - [03/Sep/2026:21:25:10 +0200] "POST //alfacgiapi/perl.alfa HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
178.128.231.0 - - [03/Sep/2026:21:25:10 +0200] "GET //file-manager/initialize HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/5
...
show less
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-03 19:00:36
(2 days ago)
Git config exposure probe
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-03 18:38:41
(2 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack