๐ฉ๐ช
big-cloud.nl
2026-09-17 10:12:12
(2 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:12:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:12:26.951394 2026] [security2:error] [pid 22892:tid 22892] [client 2a02:4780:10:26e8::1:33342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "keymarketmedia.com"] [uri "/.env.txt"] [unique_id "aquu-uSI9OGjq9TOdBXuMwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-17 08:00:52
(2 days ago)
WordPress config file probe
Web App Attack
๐ซ๐ท
thilo
2026-09-17 07:22:39
(2 days ago)
Probe for vulnerabilities. Path attempted: /wp-json/gravitysmtp/v1/tests/mock-data
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 06:36:09
(2 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:10:26e8::1 - - [17/Sep/2026:08:35:54 +0200] "GET /.env.txt HTTP/1.1" 301 453 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:17:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:17:48.487382 2026] [security2:error] [pid 24135:tid 24160] [client 2a02:4780:10:26e8::1:55594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raxelon.com"] [uri "/.git/config"] [unique_id "aqtNzG9aBDoFEy2Z6YPZ7wAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-16 23:19:49
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 21:36:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 17:36:49.561327 2026] [security2:error] [pid 13036:tid 13036] [client 2a02:4780:10:26e8::1:59252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "semisysteme.com"] [uri "/wp-config.php.orig"] [unique_id "aqsL8aVzV3OQMcKqAvufLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:43:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:43:41.926099 2026] [security2:error] [pid 29919:tid 29919] [client 2a02:4780:10:26e8::1:55952] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jonleefamily.brushmileage.org"] [uri "/wp-config.php.swp"] [unique_id "aqqA7U38v5feZywqFGrosQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:05:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:05:15.628524 2026] [security2:error] [pid 20063:tid 20063] [client 2a02:4780:10:26e8::1:50720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.english.art.mavikalem.org"] [uri "/wp-config.php.swp"] [unique_id "aqpp25XB3DnXRTZqzoQSYwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:16:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:16:48.047192 2026] [security2:error] [pid 17664:tid 17664] [client 2a02:4780:10:26e8::1:58078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nesetsv.com"] [uri "/wp-config.php.swp"] [unique_id "aqpegGLQfgY7KFW1_lFUoAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:46:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:46:01.910269 2026] [security2:error] [pid 10690:tid 10690] [client 2a02:4780:10:26e8::1:55312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healthmarkcounseling.com"] [uri "/wp-config.php~"] [unique_id "aqoQ-SmXcWDnww-w_5KHZAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-16 02:25:22
(4 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: vault.astropot.online | URI: /.env.staging | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:24:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:24:46.436591 2026] [security2:error] [pid 7357:tid 7357] [client 2a02:4780:10:26e8::1:57954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcga.golf"] [uri "/wp-config.php.swp"] [unique_id "aqmpjuBQn977z2Xu6CCuwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:53:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:10:26e8::1 (srv1124903.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:53:03.323847 2026] [security2:error] [pid 5723:tid 5723] [client 2a02:4780:10:26e8::1:36318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.femalegamblers.mobileonlinecasinos.co"] [uri "/wp-config.php.bak"] [unique_id "aqmiH83MVVfXBgfw-SvZPAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack