๐ฎ๐ณ
evicky2002
2026-07-22 06:00:00
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-07-21 22:00:35
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-20.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-07-21 05:14:21
(4 days ago)
4 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ฌ๐ง
Oakley
2026-07-21 00:36:46
(5 days ago)
(confirmed_bot_sig) Confirmed bot
Hacking
Anonymous
2026-07-20 21:34:04
(5 days ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
conseilgouz
2026-07-20 21:11:15
(5 days ago)
loe-17 : Block hidden directories=>/.git/config(/)
Hacking
๐ซ๐ท
dynamix
2026-07-20 20:30:13
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 20:14:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 16:14:32.714219 2026] [security2:error] [pid 12395:tid 12395] [client 34.138.20.121:48116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.localpetsitters.com"] [uri "/.git/config"] [unique_id "al6BqKI1yVgm3JyBOIUc5wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lnklnx
2026-07-20 19:53:07
(5 days ago)
www.lnklnx.com:443 34.138.20.121 - - [20/Jul/2026:14:53:05 -0500] "GET /.git/config HTTP/1.1" 403 38 ...
show more
www.lnklnx.com:443 34.138.20.121 - - [20/Jul/2026:14:53:05 -0500] "GET /.git/config HTTP/1.1" 403 3839 "-" "-"
...
show less
Web App Attack
๐ญ๐บ
bcsaba
2026-07-20 19:50:47
(5 days ago)
Probing for .git:
34.138.20.121 - - [20/Jul/2026:21:50:45 +0200] "GET /.git/config HTTP/1.1" 403 146 ...
show more
Probing for .git:
34.138.20.121 - - [20/Jul/2026:21:50:45 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:27:35
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:27:31.921882 2026] [security2:error] [pid 10446:tid 10446] [client 34.138.20.121:38864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lizlemos.org.rejuvenationsystems.com"] [uri "/.git/config"] [unique_id "al52oyn-m2i2kTYp0T8LWgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:00:42
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:00:37.972176 2026] [security2:error] [pid 833:tid 833] [client 34.138.20.121:41566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.livegoodherbs.com"] [uri "/.git/config"] [unique_id "al5wVeqewe3eEb60V5E0hwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:56:39
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:56:35.447583 2026] [security2:error] [pid 15900:tid 23321] [client 34.138.20.121:54320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.james.abney.info"] [uri "/.git/config"] [unique_id "al5hU2Ldkoqb9F3dPuxPEgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jakob
2026-07-20 17:48:38
(5 days ago)
modsecurity Alert: Restricted File Access Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 17:40:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.20.121 (121.20.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:39:58.339018 2026] [security2:error] [pid 1836442:tid 1836442] [client 34.138.20.121:34370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jaglady.com"] [uri "/.git/config"] [unique_id "al5dbu0KBJh42uzuVtJP6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack