๐จ๐ญ
zynex
2026-10-03 12:38:12
(6 hours ago)
CrowdSec crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 11:23:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:22:55.069582 2026] [security2:error] [pid 29908:tid 29908] [client 178.62.219.118:43368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamingofatlantis.com"] [uri "/.hg/store/00manifest.i"] [unique_id "asDlj8NvOEhOApT4qOqroAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-03 10:45:29
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
AetherFox
2026-10-03 09:10:36
(9 hours ago)
AetherFox VoidGuard detected: [Sat Oct 03 09:10:36.226628 2026] [security2:error] [pid 1093404:tid 1 ...
show more
AetherFox VoidGuard detected: [Sat Oct 03 09:10:36.226628 2026] [security2:error] [pid 1093404:tid 1093445] [client 178.62.219.118:45342] [client 178.62.219.118] ModSecurity: Access denied with code 403 (phase 1). String match ".bak" at REQUEST_URI. [file "/etc/modsecurity/AetherFox.conf"] [line "126"] [id "100070"] [msg ".bak access blocked by AetherFox VoidGuard"] [tag "custom-blocklist"] [hostname "draconigen.net"] [uri "/wp-config.php.bak"] [unique_id "asDGjPZI8Hw8nGkbHMWDMAAAABU"]
[Sat Oct 03 09:10:36.226999 2026] [security2:error] [pid 1093405:tid 1093421] [client 178.62.219.118:45346] [client 178.62.219.118] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(\\\\.aws/(credentials|config)|\\\\.ssh/(id_rsa|authorized_keys)|/config/(secrets|database)\\\\.yml|/config/environment\\\\.rb|/docker-compose\\\\.yml|/\\\\.circleci/config\\\\.yml|wp-config\\\\.(php|old|bak)|wp-config\\\\.php(~|\\\\.save|\\\\.orig)|config\\\\.inc\\\\.php\\\\.bak ..." at R
...
show less
Hacking
Bad Web Bot
๐ซ๐ท
dwmp
2026-10-03 07:58:53
(11 hours ago)
Url probing: /.gitlab-ci.yml
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-03 06:43:24
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
LRob
2026-10-03 05:35:02
(13 hours ago)
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) ...
show more
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
Anonymous
2026-10-03 05:01:26
(13 hours ago)
(caddyscan) Scanner path probe from 178.62.219.118 (NL/The Netherlands/-): 5 in the last 3600 secs; ...
show more
(caddyscan) Scanner path probe from 178.62.219.118 (NL/The Netherlands/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 178.62.219.118 - - [03/Oct/2026:05:01:02 +0000] "GET /wp-config.php.bak HTTP/1.1"
[REDACTED] 200 2627 178.62.219.118 - - [03/Oct/2026:05:01:26 +0000] "GET /.env.example HTTP/1.1"
[REDACTED] 200 2627 178.62.219.118 - - [03/Oct/2026:05:01:26 +0000] "GET /.env.php HTTP/1.1"
[REDACTED] 200 2627 178.62.219.118 - - [03/Oct/2026:05:01:26 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 178.62.219.118 - - [03/Oct/2026:05:01:26 +0000] "GET /.htaccess HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-03 04:35:57
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:35:51.609758 2026] [security2:error] [pid 11927:tid 11927] [client 178.62.219.118:38802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ospectra.ai"] [uri "/.git/config"] [unique_id "asCGJ5yW8uMO9M6fG5HNigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:20:26
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:20:21.858557 2026] [security2:error] [pid 6729:tid 6740] [client 178.62.219.118:43022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mjkotob.com"] [uri "/.git/config"] [unique_id "asB0dWDoQBa0yOrGx2SQBgAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-03 02:33:40
(16 hours ago)
177 requests with url.path */.git/config
128 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
OceanTreasure
2026-10-03 02:18:08
(16 hours ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-10-03T02:18:08Z [proxy]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 01:49:13
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 178.62.219.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:49:09.927327 2026] [security2:error] [pid 3417:tid 3417] [client 178.62.219.118:46038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diveshop-pr.com"] [uri "/.hg/store/00manifest.i"] [unique_id "asBfFdNkSaYIMA6gh0-1NgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-02 23:25:03
(19 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-10-02 23:05:31
(19 hours ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (49/60 min)'; Requests=49
Port Scan