Anonymous
2026-08-28 04:33:08
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
π³π±
homeshowdomain.nl
2026-08-23 22:01:18
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-23
Web App Attack
SSH
Hacking
πΊπΈ
ne1for23
2026-08-23 20:25:53
(1 week ago)
Attempting to probe for sensitive information accidently exposed via git config.
209.38.81.113 - - ...
show more
Attempting to probe for sensitive information accidently exposed via git config.
209.38.81.113 - - [23/Aug/2026:20:25:52 +0000] "GET /.git/config HTTP/1.1" 403 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
πΊπΈ
FreeMyIP
2026-08-23 20:15:41
(1 week ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-08-23 18:44:09
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.tech | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
π©πͺ
sdos.es
2026-08-23 14:34:27
(1 week ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
π«π·
masterguru
2026-08-23 13:45:13
(1 week ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 13:37:46
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:37:40.857424 2026] [security2:error] [pid 20950:tid 20955] [client 209.38.81.113:47090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rainbowbb.com"] [uri "/.git/config"] [unique_id "aor3pAkxFRrb7Y8gzXo2dgAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Lino Project
2026-08-23 12:55:16
(1 week ago)
209.38.81.113 - - [23/Aug/2026:14:55:13 +0200] "GET /.git/config HTTP/1.1" 302 455 "-" "Mozilla/5.0 ...
show more
209.38.81.113 - - [23/Aug/2026:14:55:13 +0200] "GET /.git/config HTTP/1.1" 302 455 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MyGlobalFlowers
2026-08-23 12:21:40
(1 week ago)
Multiple WAF Violations
Web App Attack
πΏπ¦
conure.sh
2026-08-23 12:11:04
(1 week ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 2 domain(s) in 1s
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 12:03:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:02:59.102626 2026] [security2:error] [pid 20865:tid 20865] [client 209.38.81.113:33470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "relationshipecology.com"] [uri "/.git/config"] [unique_id "aorhc0_6ctH2YTEkOQqR9wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-08-23 11:50:18
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 11:41:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.81.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:41:37.914839 2026] [security2:error] [pid 16711:tid 16711] [client 209.38.81.113:42114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "peaceriverfishing.com"] [uri "/.git/config"] [unique_id "aorccUshmceKQyrG-Yac0wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2026-08-23 11:31:47
(1 week ago)
2026/08/23 13:31:47 [error] 88791#101108: *3412860 access forbidden by rule, client: 209.38.81.113, ...
show more
2026/08/23 13:31:47 [error] 88791#101108: *3412860 access forbidden by rule, client: 209.38.81.113, server: revolutionbim.com, request: "GET /.git/config HTTP/1.1", host: "revolutionbim.com"
...
show less
Web Spam