🇮🇳
evicky2002
2026-08-18 07:13:36
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇳🇿
Antinson
2026-08-17 20:48:35
(2 weeks ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-08-17 20:47:59
(2 weeks ago)
[17/Aug/2026:23:47:58 +0300] -- 194.146.92.120 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
🇯🇵
ki3
2026-08-17 20:06:40
(2 weeks ago)
Fail2Ban: Web App Attacks and Forum Spam 194.146.92.120 1786997199.0(JST)
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 19:00:16
(2 weeks ago)
File repository snooping:
194.146.92.120 - - [17/Aug/2026:19:00:16 +0000] "GET /.git/config HTTP/1. ...
show more
File repository snooping:
194.146.92.120 - - [17/Aug/2026:19:00:16 +0000] "GET /.git/config HTTP/1.1" 404 234 "http://[sub domain]/.git/config" "Go-http-client/1.1"
show less
Hacking
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-17 18:15:10
(2 weeks ago)
[Tue Aug 18 04:15:09.266298 2026] [security2:error] [pid 145520] [client 194.146.92.120:25793] [clie ...
show more
[Tue Aug 18 04:15:09.266298 2026] [security2:error] [pid 145520] [client 194.146.92.120:25793] [client 194.146.92.120] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ccideas.com.au"] [uri "/.git/config"] [unique_id "aoNPrRYjzXhfvU8qvdl5WAAAABA"], referer: http://ccideas.com.au/.git/config
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 10:27:04
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:26:56.705739 2026] [security2:error] [pid 21580:tid 21580] [client 194.146.92.120:31821] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "worthhistory.org"] [uri "/.git/config"] [unique_id "aoLh8KBECsB8PLoJIRmLUwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 10:07:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 06:07:16.826406 2026] [security2:error] [pid 8877:tid 8877] [client 194.146.92.120:23187] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kln.ne.jp"] [uri "/.git/config"] [unique_id "aoLdVBCZ706RIsH6b6E6YAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 09:25:45
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:25:41.595814 2026] [security2:error] [pid 2062:tid 2062] [client 194.146.92.120:64587] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seychelles-boat-registration.com"] [uri "/.git/config"] [unique_id "aoLTlfgyTlMGqcHOs_rCTgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 09:05:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 194.146.92.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:05:34.857371 2026] [security2:error] [pid 7756:tid 7756] [client 194.146.92.120:36617] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kerrywood.com"] [uri "/.git/config"] [unique_id "aoLO3nAKnq3XM3rgUtrdDgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-08-17 07:23:31
(2 weeks ago)
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (110 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "go-http-client" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
🇭🇺
Adorjan Daczo
2026-08-17 07:07:36
(2 weeks ago)
Probe for vulnerabilities. Path attempted: /.git/config
Web App Attack
🇩🇪
LRob
2026-08-17 07:00:17
(2 weeks ago)
Credential and secrets file probing | req: /.git/config | UA: Go-http-client/1.1
Hacking
Web App Attack
🇩🇪
pltcldvlpr
2026-08-17 06:55:10
(2 weeks ago)
CMS/framework probe: 194.146.92.120 - - [17/Aug/2026:08:55:08 +0200] "GET /.git/config HTTP/1.1" 301 ...
show more
CMS/framework probe: 194.146.92.120 - - [17/Aug/2026:08:55:08 +0200] "GET /.git/config HTTP/1.1" 301 178 "-" "Go-http-client/1.1" asn=212238 org="Datacamp Limited" country=ES
...
show less
Web App Attack
Anonymous
2026-08-17 05:31:12
(2 weeks ago)
Web Server Exposed Git Repository Information Disclosure.
Hacking