π«π·
regishoussin
2026-09-17 19:05:29
(2 days ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-17 19:05 UTC.
show less
Bad Web Bot
Web App Attack
πΊπΈ
interbiznw.com
2026-09-17 15:55:17
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
π³π±
mieg
2026-09-17 15:23:40
(2 days ago)
Web vulnerability probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 14:49:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:49:04.675184 2026] [security2:error] [pid 18879:tid 18879] [client 2a02:6ea0:1508:2::d001:55716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cortona.ws"] [uri "/.git/index"] [unique_id "aqv94LK1XWG9AEiSw900gAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 11:52:29
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:949110) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:52:25.074223 2026] [security2:error] [pid 32395:tid 32395] [client 2a02:6ea0:1508:2::d001:40450] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "chuckwagon.org"] [uri "/.git/index"] [unique_id "aqvUeXTTQ6PCT0oQPNXZ0AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 10:26:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 06:26:49.738889 2026] [security2:error] [pid 28821:tid 28821] [client 2a02:6ea0:1508:2::d001:34704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centuryabsinthe.com"] [uri "/.git/index"] [unique_id "aqvAaTck4PLWMTs76TIccQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 08:15:36
(3 days ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto.gr.log; samples=/.git/index
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 08:01:36
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:01:30.907342 2026] [security2:error] [pid 25395:tid 25395] [client 2a02:6ea0:1508:2::d001:41130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cameronwv.com"] [uri "/.git/index"] [unique_id "aqueWpI0UDCLE51un-cn2QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 05:51:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:51:45.043298 2026] [security2:error] [pid 5865:tid 5865] [client 2a02:6ea0:1508:2::d001:46086] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bowerwood.com"] [uri "/.git/index"] [unique_id "aqt_8amSCu9E-GGrS_iiVwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-17 05:17:08
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π³π±
Alt255
2026-09-17 05:16:44
(3 days ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2a02:6ea0:1508:2::d001 - - [17/Sep/2026:07:16:29 +0200] "GET /.git/index HTTP/2.0" 404 401 "-" "moving-to-bins/1.0"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 05:11:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:11:17.659968 2026] [security2:error] [pid 28405:tid 28405] [client 2a02:6ea0:1508:2::d001:52080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boblog111.com"] [uri "/.git/index"] [unique_id "aqt2dZE1fW72KSEv-GwESAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 03:47:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:47:37.939528 2026] [security2:error] [pid 21187:tid 21187] [client 2a02:6ea0:1508:2::d001:57948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigredgraphicdesign.com"] [uri "/.git/index"] [unique_id "aqti2c5HM9Nq_xUPlM0zdgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 02:02:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a02:6ea0:1508:2::d001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:02:11.015944 2026] [security2:error] [pid 11231:tid 11231] [client 2a02:6ea0:1508:2::d001:54072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "batw.net"] [uri "/.git/index"] [unique_id "aqtKIz3lSnyUMPUn7kvzywAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Major Hostility
2026-09-16 22:53:22
(3 days ago)
"GET /.git/index HTTP/1.1" 404
"GET /.git/index HTTP/1.1" 404
Web App Attack