🇩🇪
SiyCah
2026-09-07 03:00:01
(23 hours ago)
IP banned by fail2ban; banned in jail apache-modsecurity. Report generated by fail2abuseipdb.
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-07 00:06:12
(1 day ago)
Bot / seems abusive / Apache connections: 29
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-07 00:05:13
(1 day ago)
IM360 WAF: Hidden file access
Brute-Force
🇮🇹
Inartis
2026-09-07 00:03:29
(1 day ago)
193.233.219.54 - - [07/Sep/2026:02:03:19 +0200] "GET /.git/config HTTP/1.1" 403 748 "-" "Mozilla/5.0 ...
show more
193.233.219.54 - - [07/Sep/2026:02:03:19 +0200] "GET /.git/config HTTP/1.1" 403 748 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
193.233.219.54 - - [07/Sep/2026:02:03:27 +0200] "GET /.env HTTP/1.1" 403 748 "https://termepatria.it/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
193.233.219.54 - - [07/Sep/2026:02:03:27 +0200] "GET /.env.production HTTP/1.1" 403 748 "https://termepatria.it/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 23:56:11
(1 day ago)
[ns19.kdns.gr] httpd-config-scan: sites=www.techsupportltd.gr; logs=/var/log/httpd/domains/techsuppo ...
show more
[ns19.kdns.gr] httpd-config-scan: sites=www.techsupportltd.gr; logs=/var/log/httpd/domains/techsupportltd.gr.log; samples=/.git/config | /img../.git/config | /images../.git/config
show less
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-06 23:55:14
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.tech | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-06 23:47:10
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
LRob
2026-09-06 23:41:45
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /content../.git/config (+11 more) | 2026-09-06 23:41 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-06 23:39:59
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇦🇺
paulshipley.com.au
2026-09-06 23:35:56
(1 day ago)
[Mon Sep 07 09:35:56.570010 2026] [security2:error] [pid 29283] [client 193.233.219.54:64016] [clien ...
show more
[Mon Sep 07 09:35:56.570010 2026] [security2:error] [pid 29283] [client 193.233.219.54:64016] [client 193.233.219.54] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "talentaymerch.com.au"] [uri "/.git/index"] [unique_id "ap343JdPzPn8PqCfoXnAyAAAAAc"]
...
show less
Web App Attack
🇩🇪
nyt
2026-09-06 23:29:49
(1 day ago)
Sensitive File Probe
Web App Attack
🇧🇪
cmbplf
2026-09-06 23:28:06
(1 day ago)
2.255 requests with url.path */.git/config
1.280 requests with url.path *.git/*
336 requests with ...
show more
2.255 requests with url.path */.git/config
1.280 requests with url.path *.git/*
336 requests with url.path *.aws/*
136 requests with url.path *.azure/*
show less
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 23:16:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 193.233.219.54 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 193.233.219.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:16:00.553518 2026] [security2:error] [pid 10009:tid 10009] [client 193.233.219.54:18860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "superzilla.com"] [uri "/.git/HEAD"] [unique_id "ap30MJ6ksLDeUlHkBCr9cQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
suble.org
2026-09-06 23:06:05
(1 day ago)
193.233.219.54 - - [07/Sep/2026:01:06:04 +0200] "GET http://169.254.169.254/latest/meta-data/identit ...
show more
193.233.219.54 - - [07/Sep/2026:01:06:04 +0200] "GET http://169.254.169.254/latest/meta-data/identity-credentials/ec2/security-credentials/ec2-instance HTTP/1.1" 503 23347 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
🇳🇱
Savvii
2026-09-06 23:04:45
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack