๐บ๐ธ
TPI-Abuse
2026-08-18 16:46:25
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 12:46:18.532332 2026] [security2:error] [pid 9289:tid 9289] [client 178.175.128.39:54165] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marxistphilosophy.org"] [uri "/.git/config"] [unique_id "aoSMWk9nYRhzuqjydiVzyAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-08-18 15:55:11
(1 hour ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 15:29:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 11:28:56.398160 2026] [security2:error] [pid 25150:tid 25150] [client 178.175.128.39:25897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mayflowersgifts.com"] [uri "/.git/config"] [unique_id "aoR6OCZm4BN-Hj7dE-oqXgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 15:06:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 11:06:34.229129 2026] [security2:error] [pid 9861:tid 9861] [client 178.175.128.39:54499] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosplayculture.com"] [uri "/.git/config"] [unique_id "aoR0-gLxmLouUISVPwTmAQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 14:45:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:45:33.202285 2026] [security2:error] [pid 13043:tid 13043] [client 178.175.128.39:26185] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1st-advantage-arkansas-real-estate-school.com"] [uri "/.git/config"] [unique_id "aoRwDYDP2i_hkRiSkiECygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Balthasar Morpheus Jรถrmundur (JKweb Service)
2026-08-18 13:11:02
(4 hours ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 12:35:25
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:35:18.279991 2026] [security2:error] [pid 7938:tid 7938] [client 178.175.128.39:55509] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gunningphysio.com"] [uri "/.git/config"] [unique_id "aoRRht-_Qbf6W_JwsEZijwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 12:10:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.175.128.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:10:18.960484 2026] [security2:error] [pid 4725:tid 4725] [client 178.175.128.39:22305] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amychop.com"] [uri "/.git/config"] [unique_id "aoRLqhxjGDccbxTIyOFDzwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-18 12:00:39
(5 hours ago)
[TueAug1814:00:35.7316862026][security2:error][pid3174120:tid3176660][client178.175.128.39:0]ModSecu ...
show more
[TueAug1814:00:35.7316862026][security2:error][pid3174120:tid3176660][client178.175.128.39:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"465\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"vetreriaperletti.ch\"][uri\"/.git/config\"][unique_id\"aoRJY3tUsKBy0SjvrLaMzwAAAM0\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-18 11:40:17
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
YF
2026-08-18 11:15:28
(6 hours ago)
Git config exposure probe
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-18 10:39:02
(6 hours ago)
[18/Aug/2026:13:39:02 +0300] -- 178.175.128.39 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-08-18 09:44:40
(7 hours ago)
dot file probe
Web App Attack
๐ฉ๐ช
LRob
2026-08-18 09:31:09
(7 hours ago)
Credential and secrets file probing | req: /.git/config | UA: Go-http-client/2.0
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-07-20 10:40:22
(4 weeks ago)
Web attack/malicious scanning detected
Web App Attack