Anonymous
2026-08-28 04:32:20
(1 week ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇳🇱
BlueWire Hosting
2026-08-21 23:59:38
(2 weeks ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 23:30:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:30:09.699312 2026] [security2:error] [pid 22579:tid 22579] [client 185.193.167.101:32727] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manty.com"] [uri "/.git/config"] [unique_id "aojfgR9_fSvn3YbKTayIHAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
london2038.com
2026-08-21 22:01:14
(2 weeks ago)
Probing for exploits
185.193.167.101 - - [22/Aug/2026:00:01:10 +0200] "GET /.git/config HTTP/1.1" 42 ...
show more
Probing for exploits
185.193.167.101 - - [22/Aug/2026:00:01:10 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
185.193.167.101 - - [22/Aug/2026:00:01:10 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
show less
Hacking
Web App Attack
Anonymous
2026-08-21 20:58:17
(2 weeks ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-08-21 20:30:25
(2 weeks ago)
GET /.git/config HTTP/1.1
...
Web App Attack
🇧🇪
madeit
2026-08-21 15:29:49
(2 weeks ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 13:09:10
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 09:09:05.066025 2026] [security2:error] [pid 8276:tid 8276] [client 185.193.167.101:31221] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.quakeprediction.com"] [uri "/.git/config"] [unique_id "aohN8XTqzzs575xlLgW-NwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-21 13:04:50
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config
show less
Hacking
Web App Attack
🇩🇪
ghostwarriors
2026-08-21 12:50:44
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-21 12:16:05
(2 weeks ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇪🇸
el-brujo
2026-08-21 11:01:41
(2 weeks ago)
21/Aug/2026:13:01:40.977409 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
21/Aug/2026:13:01:40.977409 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 185.193.167.101] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "papyre.elhacker.info"] [uri "/.git/config"] [unique_id "aogwFAw7_6rLxlxAuJG-6gAABE4"]
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-21 10:50:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 185.193.167.101 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:50:06.369111 2026] [security2:error] [pid 10898:tid 10898] [client 185.193.167.101:27335] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3905ccn.org"] [uri "/.git/config"] [unique_id "aogtXgSqdInwlusWrF-CTgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
IT Infraestructura
2026-08-21 09:38:00
(2 weeks ago)
Illegal Resource Access Request blocked to URL: /.git/config(GET)
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-21 07:28:14
(2 weeks ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 0s
Web App Attack