๐บ๐ธ
MuttMutt
2026-05-13 14:30:00
(3 months ago)
Aggressive automated vulnerability reconnaissance (23.79k requests) originating from The Infrastruct ...
show more
Aggressive automated vulnerability reconnaissance (23.79k requests) originating from The Infrastructure Group B.V. (Netherlands). The actor is executing a massive HEAD-request dictionary scan for sensitive administrative APIs, documentation, and configuration files, including /api/swagger, /rest/settings, and /api/v1/apikey across multiple subdomains (mail, ftp, etc.). Traffic is highly automated and mostly bypassed standard challenges.
show less
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-05-13 07:52:03
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-13 06:41:18
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 02:41:08.227497 2026] [security2:error] [pid 22514:tid 22514] [client 2a04:52c0:122:d2f9::1:45644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.consorciolegal.com"] [uri "/.git/config"] [unique_id "agQdBGxXEDRv8HKW0qzpRwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 23:24:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 19:24:18.219549 2026] [security2:error] [pid 30254:tid 30254] [client 2a04:52c0:122:d2f9::1:42970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.gitignore" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.utilis.net"] [uri "/.gitignore"] [unique_id "agJlIocqX-z2yfTVWNIh9wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-10 23:32:00
(4 months ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-09 22:10:23
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 18:10:14.849922 2026] [security2:error] [pid 3449:tid 3449] [client 2a04:52c0:122:d2f9::1:57888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.njletr.org"] [uri "/.git/config"] [unique_id "af-wxsXHil4rpXoVP0rl6gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 20:05:49
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:210492) triggered by 2a04:52c0:122:d2f9::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 16:05:38.666984 2026] [security2:error] [pid 19663:tid 19663] [client 2a04:52c0:122:d2f9::1:54716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.omnithermal.com"] [uri "/.git/config"] [unique_id "af-TkvbzD7IjmHgKjVH4yQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-08 03:31:05
(4 months ago)
889 limiting connections by zone (12m59s)
DDoS Attack
๐ฉ๐ช
SCHAPPY
2026-05-03 11:00:03
(4 months ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-03 09:03:33
(4 months ago)
Try to access /.env
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-04-28 05:21:35
(4 months ago)
[Mon Apr 27 23:19:44.536924 2026] [authz_core:error] [pid 259833:tid 140276097095232] [client 2a04:5 ...
show more
[Mon Apr 27 23:19:44.536924 2026] [authz_core:error] [pid 259833:tid 140276097095232] [client 2a04:52c0:122:d2f9::1:40618] AH01630: client denied by server configuration: /var/www/public_html/board/wp-config.php.bak
[Mon Apr 27 23:21:34.943709 2026] [authz_core:error] [pid 259567:tid 140275712259648] [client 2a04:52c0:122:d2f9::1:58840] AH01630: client denied by server configuration: /var/www/public_html/board/.env.vault
[Mon Apr 27 23:21:34.946101 2026] [authz_core:error] [pid 259567:tid 140275712259648] [client 2a04:52c0:122:d2f9::1:58840] AH01630: client denied by server configuration: /var/www/public_rsrc/assets/RMBS-Server-Error.html
...
show less
Bad Web Bot
๐บ๐ธ
pduggusa
2026-04-28 03:35:52
(4 months ago)
Detected attacking dugganusa.com at 2026-04-28T03:35:52.782Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
pduggusa
2026-04-28 02:32:54
(4 months ago)
Detected attacking dugganusa.com at 2026-04-28T02:32:54.836Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
pduggusa
2026-04-28 01:33:05
(4 months ago)
Detected attacking dugganusa.com at 2026-04-28T01:33:05.758Z | Source: DugganUSA PreCog auto-block
Hacking
๐บ๐ธ
pduggusa
2026-04-28 00:34:44
(4 months ago)
Detected attacking dugganusa.com at 2026-04-28T00:34:44.578Z | Source: DugganUSA PreCog auto-block
Hacking