๐ฉ๐ช
AetherFox
2026-09-17 17:52:48
(1 week ago)
AetherFox VoidGuard detected: [Thu Sep 17 17:52:45.595155 2026] [authz_core:error] [pid 2761859:tid ...
show more
AetherFox VoidGuard detected: [Thu Sep 17 17:52:45.595155 2026] [authz_core:error] [pid 2761859:tid 2761885] [client 2a02:4780:14:c8d8::1:51044] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Thu Sep 17 17:52:45.646011 2026] [authz_core:error] [pid 2761859:tid 2761875] [client 2a02:4780:14:c8d8::1:51032] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git/config
[Thu Sep 17 17:52:46.308890 2026] [authz_core:error] [pid 2761858:tid 2761868] [client 2a02:4780:14:c8d8::1:59462] AH01630: client denied by server configuration: proxy:http://[MASKED]/.git/config
[Thu Sep 17 17:52:46.309193 2026] [authz_core:error] [pid 2761858:tid 2761868] [client 2a02:4780:14:c8d8::1:59462] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Thu Sep 17 17:52:48.263106 2026] [authz_core:error] [pid 2761858:tid 2761897] [client 2a02:4780:14:c8d8::1:59446] AH01630: client denied by server configuration:
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-17 08:24:20
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.definitelynotahoneypot.xyz | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:24:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:24:16.187543 2026] [security2:error] [pid 30160:tid 30228] [client 2a02:4780:14:c8d8::1:55080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.danbressler.com"] [uri "/.git/config"] [unique_id "aqujsNW3ouMg-zosCZz5nQAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-17 05:30:50
(1 week ago)
Git config exposure probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 05:22:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:22:26.312538 2026] [security2:error] [pid 15950:tid 15950] [client 2a02:4780:14:c8d8::1:40136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-uk.com"] [uri "/.git/config"] [unique_id "aqt5EtGvj4YM4avEqg2u9QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VanKoh
2026-09-17 02:44:02
(1 week ago)
2a02:4780:14:c8d8::1 - - [16/Sep/2026:20:43:56 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "M ...
show more
2a02:4780:14:c8d8::1 - - [16/Sep/2026:20:43:56 -0600] "GET /wp-config.php.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:14:c8d8::1 - - [16/Sep/2026:20:43:59 -0600] "GET /wp-config.php~ HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a02:4780:14:c8d8::1 - - [16/Sep/2026:20:44:01 -0600] "GET /wp-config.php.save HTTP/1.1" 301 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 07:27:18
(1 week ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:4780:14:c8d8::1 - - [16/Sep/2026:09:26:58 +0200] "GET /wp-config.php.orig HTTP/1.1" 404 102924 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:18:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:18:33.794754 2026] [security2:error] [pid 21175:tid 21175] [client 2a02:4780:14:c8d8::1:55018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mardensmith.com"] [uri "/wp-config.php.txt"] [unique_id "aqmoGX9dsfoetixi5oeUJwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 20:03:14
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: kibana.budyn.xyz | URI: /.env.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:10:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:10:04.509438 2026] [security2:error] [pid 2424:tid 2424] [client 2a02:4780:14:c8d8::1:54970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.taylorandatlantic.net"] [uri "/.env.txt"] [unique_id "aqmYDG1X2k5KUMY0KUr8VgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:52:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:52:16.503198 2026] [security2:error] [pid 21969:tid 21969] [client 2a02:4780:14:c8d8::1:43944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dwars.net"] [uri "/.git/config"] [unique_id "aqkxcHNgAbbkj1Jl26TAKAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 09:34:38
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:34:33.332346 2026] [security2:error] [pid 29109:tid 29109] [client 2a02:4780:14:c8d8::1:52778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brazilianbottom.com"] [uri "/wp-config.php.orig"] [unique_id "aqkRKTiOBNgMSVSvEBMQTAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:14:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:14:12.587342 2026] [security2:error] [pid 4976:tid 4976] [client 2a02:4780:14:c8d8::1:35568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ryanc.net"] [uri "/.env.production"] [unique_id "aqj-VIGMJpOxOU_rQ9oEkAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:51:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:51:06.812803 2026] [security2:error] [pid 3549:tid 3549] [client 2a02:4780:14:c8d8::1:59928] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.oruhu.org"] [uri "/.env.save"] [unique_id "aqj46rd9sTmpi8br1_xpYgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:26:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:4780:14:c8d8::1 (srv738630.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:26:02.407702 2026] [security2:error] [pid 10862:tid 10862] [client 2a02:4780:14:c8d8::1:57442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.juniperhills.net"] [uri "/.env.txt"] [unique_id "aqjzCmGI72Donw3xsg3YJwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack