π«π·
spot
2026-09-29 19:21:53
(20 minutes ago)
198.211.97.206 - - [29/Sep/2026:20:21:52 +0100] "GET /.git/config HTTP/1.1" 301 608 "-" "Mozilla/5.0 ...
show more
198.211.97.206 - - [29/Sep/2026:20:21:52 +0100] "GET /.git/config HTTP/1.1" 301 608 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
Hacking
π«π·
regishoussin
2026-09-29 18:57:41
(44 minutes ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-29 18:57 UTC.
show less
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-09-29 18:21:27
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
Charlesiv
2026-09-29 18:00:57
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-29T16:05:14Z
Ray ID: a42c3a6f48ec6a5e
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 14:07:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 10:07:11.646686 2026] [security2:error] [pid 23209:tid 23209] [client 198.211.97.206:45606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crowleywoodworking.com"] [uri "/.git/config"] [unique_id "arvGD9Xy_mdcZ8VOjB6Y3gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
iulianh
2026-09-29 13:17:48
(6 hours ago)
80,443
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-29 13:17:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:17:15.716926 2026] [security2:error] [pid 5651:tid 5651] [client 198.211.97.206:35544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyphersites.com"] [uri "/.git/config"] [unique_id "aru6W1Vo1vp7bSet63WGaQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 12:53:22
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:53:19.771381 2026] [security2:error] [pid 32227:tid 32227] [client 198.211.97.206:60964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edscontracting.com"] [uri "/.git/config"] [unique_id "aru0v2vphMxWSzoHkdeImQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 11:52:44
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 07:52:36.539292 2026] [security2:error] [pid 14902:tid 14902] [client 198.211.97.206:49352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christinaetran.com"] [uri "/.git/config"] [unique_id "arumhO1v_mo8LII5z8m3TgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 11:37:22
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 07:37:14.646803 2026] [security2:error] [pid 23581:tid 23581] [client 198.211.97.206:37826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dc406.org"] [uri "/.git/config"] [unique_id "arui6vLUKk8Csm7Xvt9tQwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-29 11:00:38
(8 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:44:42
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:44:35.524416 2026] [security2:error] [pid 5312:tid 5312] [client 198.211.97.206:50248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chipnado.com"] [uri "/.git/config"] [unique_id "aruWkwvLBomxBH8QD7WQrAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 10:24:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.211.97.206 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:24:22.040870 2026] [security2:error] [pid 9469:tid 9469] [client 198.211.97.206:49066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drunkenmonkeystyle.com"] [uri "/.git/config"] [unique_id "aruR1nFrR5is735sTzFSVwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-29 09:51:06
(9 hours ago)
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebK ...
show more
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Hacking
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-29 09:02:27
(10 hours ago)
[29/Sep/2026:12:02:26 +0300] -- 198.211.97.206 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[29/Sep/2026:12:02:26 +0300] -- 198.211.97.206 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack