๐ฉ๐ช
rzk
2026-07-02 04:26:03
(3 weeks ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: NOHAVPS-LLC. Country: US. Timestamp: 2026-07-02T04:26:03+00:00.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 23:54:32
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 19:54:23.553685 2026] [security2:error] [pid 28837:tid 28837] [client 2602:f8ea:1:d::a:47008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moanddoyle.michaelprussin.com"] [uri "/.git/HEAD"] [unique_id "akWory25W9ceJtTzWpULPgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-01 23:47:48
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 23:25:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 19:25:36.784991 2026] [security2:error] [pid 2629:tid 2651] [client 2602:f8ea:1:d::a:60030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mediacrafts.iancaird.com"] [uri "/.git/HEAD"] [unique_id "akWh8NgHLLl7roePr3cV2QAAAMw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 22:35:30
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 18:35:20.634926 2026] [security2:error] [pid 18350:tid 18361] [client 2602:f8ea:1:d::a:54326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "motoadvrally.com.getairborne.com"] [uri "/.git/HEAD"] [unique_id "akWWKP0_24VPBuhY8rn6igAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-07-01 22:14:31
(3 weeks ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 22:07:22
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 18:07:13.082399 2026] [security2:error] [pid 12758:tid 12758] [client 2602:f8ea:1:d::a:36474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m.closedfortheseason.com"] [uri "/.git/HEAD"] [unique_id "akWPkQMnq9FVYaYXXFUH2AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-07-01 22:06:51
(3 weeks ago)
2602:f8ea:1:d::a - - [01/Jul/2026:23:06:50 +0100] 443 "GET /.git/HEAD HTTP/1.1" 404 25728 "https://m ...
show more
2602:f8ea:1:d::a - - [01/Jul/2026:23:06:50 +0100] 443 "GET /.git/HEAD HTTP/1.1" 404 25728 "https://myintarweb.co.uk/.git/HEAD" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:149.0) Gecko/20100101 Firefox/149.0"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 21:25:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 17:25:28.148353 2026] [security2:error] [pid 32751:tid 32751] [client 2602:f8ea:1:d::a:34664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "md-ehr.drxcontent.com"] [uri "/.git/HEAD"] [unique_id "akWFyBHcEgSzwSrFFE42JwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 20:33:04
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 16:32:56.494879 2026] [security2:error] [pid 4930:tid 4930] [client 2602:f8ea:1:d::a:38644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morethanvoting.com.lakesidedetectiveagency.com"] [uri "/.git/HEAD"] [unique_id "akV5eBFtPHA4szeihWRIPgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-07-01 20:25:38
(3 weeks ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 20:01:12
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 16:01:04.968307 2026] [security2:error] [pid 20729:tid 20729] [client 2602:f8ea:1:d::a:34702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memoriesmusic.net.controvac.com"] [uri "/.git/HEAD"] [unique_id "akVyAH6hNBY5sRWpMjKSmwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 19:41:34
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 15:41:27.180656 2026] [security2:error] [pid 29444:tid 29444] [client 2602:f8ea:1:d::a:36894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miele.pamplonaserviciotecnico.com"] [uri "/.git/HEAD"] [unique_id "akVtZ1545PA5Tfi7Amh-MwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 19:25:20
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 15:25:15.229215 2026] [security2:error] [pid 26953:tid 26953] [client 2602:f8ea:1:d::a:52184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moontouchmassage.leadek.com"] [uri "/.git/HEAD"] [unique_id "akVpm9w4yGQ1jcMh35xCXQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 19:06:56
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:f8ea:1:d::a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 15:06:50.768932 2026] [security2:error] [pid 31030:tid 31030] [client 2602:f8ea:1:d::a:43926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maps.marat.info"] [uri "/.git/HEAD"] [unique_id "akVlSv-eUrfVTWhYqJVjiAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack