๐ณ๐ฑ
Alt255
2026-09-24 14:22:55
(16 minutes ago)
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 19 ...
show more
[ti-tinov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 198.11.53.120 - - \[24/Sep/2026:16:22:39 +0200\] "GET /.git/HEAD HTTP/1.1" 404 7194 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 14:10:28
(28 minutes ago)
198.11.53.120 - - [24/Sep/2026:14:10:28 +0000] "GET /.git/HEAD HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Wi ...
show more
198.11.53.120 - - [24/Sep/2026:14:10:28 +0000] "GET /.git/HEAD HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "198.11.53.120" "-"
...
show less
Web App Attack
๐ฉ๐ช
4server
2026-09-24 13:52:07
(47 minutes ago)
[ThuSep2415:51:55.4441372026][security2:error][pid3742852:tid3742894][client198.11.53.120:0]ModSecur ...
show more
[ThuSep2415:51:55.4441372026][security2:error][pid3742852:tid3742894][client198.11.53.120:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"sanierung-pilzen-schimmel-schweiz.ch\"][uri\"/.git/HEAD\"][unique_id\"arUq-7nfL_WSwMwxyAVq5QAAAEY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 13:45:58
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 09:45:40.563602 2026] [security2:error] [pid 26678:tid 26678] [client 198.11.53.120:33177] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biomechanicalwars.com"] [uri "/.git/HEAD"] [unique_id "arUphFETt6WoOUAFG6T82gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 12:16:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:16:22.924386 2026] [security2:error] [pid 21276:tid 21276] [client 198.11.53.120:36391] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblestudentfiles.org"] [uri "/.git/HEAD"] [unique_id "arUUlg864DPWip1aO4VJ_QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 11:54:17
(2 hours ago)
Web application attack detected.
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-24 11:11:22
(3 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐ฉ๐ช
rh24
2026-09-24 09:54:26
(4 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 198.11.53.120 (US/United States/-)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 09:35:46
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:35:30.286487 2026] [security2:error] [pid 23754:tid 23754] [client 198.11.53.120:36519] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marydealfineart.com"] [uri "/.git/config"] [unique_id "arTu4tQaSTqBc2ZlfaZiWwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:59:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:58:58.867540 2026] [security2:error] [pid 19690:tid 19690] [client 198.11.53.120:46327] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "electricmeatgrinder.com"] [uri "/.git/config"] [unique_id "arTmUvpZE4ZbkmthXDrKbgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:13:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:13:30.890500 2026] [security2:error] [pid 15706:tid 15706] [client 198.11.53.120:50213] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smallbizreorg.com"] [uri "/.git/config"] [unique_id "arTbqmNYJbOUkyvuEPlHIwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:02:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 198.11.53.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:02:03.958710 2026] [security2:error] [pid 30278:tid 30278] [client 198.11.53.120:36481] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "airdeluxemusic.com"] [uri "/.git/config"] [unique_id "arTK6_xIvu0mhYBLvVy91AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 06:39:02
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/HEAD HTTP/1.1, GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
CBJ
2026-09-24 06:20:08
(8 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-24 05:14:30
(9 hours ago)
2 attacks on VC URLs:
GET /.git/HEAD HTTP/1.1
Hacking