|
๐ซ๐ฎ
inlink.ltd
|
|
Known malicious PHP file or CMS probe
|
Web App Attack
|
|
|
๐ฉ๐ช
Lino Project
|
|
193.56.28.17 - - [09/May/2026:05:19:56 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3972 "https://www.primo ...
show more
193.56.28.17 - - [09/May/2026:05:19:56 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3972 "https://www.primobio.it/mio-account/?action=register" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
Lino Project
|
|
193.56.28.17 - - [06/May/2026:04:08:38 +0200] "GET /wp-admin/post-new.php HTTP/1.1" 403 6488 "https: ...
show more
193.56.28.17 - - [06/May/2026:04:08:38 +0200] "GET /wp-admin/post-new.php HTTP/1.1" 403 6488 "https://www.primobio.it/mio-account/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ธ๐ช
KIDOS
|
|
malicious activity
|
Web App Attack
|
|
|
๐ฆ๐บ
RedBear IT
|
|
"DDoS against public endpoint"
|
DDoS Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 07:17:13.296649 2026] [security2:error] [pid 28235:tid 28235] [client 193.56.28.17:23051] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teknna.com"] [uri "/api/.git/config"] [unique_id "aZG5STpY2qEoxRvKXqW_jgAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ธ๐ฌ
anotherwatcher
|
|
bad bot
|
Bad Web Bot
|
|
|
๐บ๐ธ
myagent.site
|
|
Blocking for trying to access an exploit file: /site/.git/config
|
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 23:05:30.062862 2026] [security2:error] [pid 7989:tid 7989] [client 193.56.28.17:12933] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stonesandbones.net"] [uri "/.env.local"] [unique_id "aZFGClWqeq5KdkRap1eWowAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 22:42:34.895416 2026] [security2:error] [pid 25934:tid 25934] [client 193.56.28.17:55075] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stenbot.com"] [uri "/new/.git/config"] [unique_id "aZFAqlsAE6tkezp_By9HIQAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 21:32:16.585449 2026] [security2:error] [pid 25345:tid 25345] [client 193.56.28.17:55131] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiritofacorn.com"] [uri "/app/.git/config"] [unique_id "aZEwML7aUbZiT0cjJBLYDwAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
ParaBug
|
|
193.56.28.17 - - [15/Feb/2026:03:31:58 +0100] "GET /test/.git/config HTTP/1.1" 301 4237 "-" "Mozilla ...
show more
193.56.28.17 - - [15/Feb/2026:03:31:58 +0100] "GET /test/.git/config HTTP/1.1" 301 4237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
|
Phishing
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
Carsten
|
|
GET [backup/.git/config]
|
Port Scan
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:45:20.689510 2026] [security2:error] [pid 8789:tid 8789] [client 193.56.28.17:57575] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mp3tracks.com"] [uri "/dev/.git/config"] [unique_id "aZEXIGt1QZcBkKPJVzstbwAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 193.56.28.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 14 19:29:54.981001 2026] [security2:error] [pid 1034326:tid 1034326] [client 193.56.28.17:58081] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lowrygroup.com"] [uri "/admin/.git/config"] [unique_id "aZETgg22zlidkk5lArknCgAAABw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|