๐ฎ๐ณ
evicky2002
2026-05-20 04:30:47
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-05-09 21:59:12
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-08.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
Peter-Johann Sarbach
2026-05-09 05:47:15
(1 month ago)
Hacking website
Hacking
๐จ๐ญ
TheCoon
2026-05-08 07:00:02
(1 month ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ฐ
RhQM
2026-05-08 06:21:29
(1 month ago)
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-05-08 06:15:16
(1 month ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 06:11:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 02:11:42.553119 2026] [security2:error] [pid 2015:tid 2015] [client 34.146.252.145:48330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.serenimedit.com"] [uri "/.git/config"] [unique_id "af1-ntY7hPc5spUGD6zfOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-08 05:01:40
(1 month ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 05:01:35
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 01:01:32.392546 2026] [security2:error] [pid 22810:tid 22810] [client 34.146.252.145:33214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trademartghana.com"] [uri "/.git/config"] [unique_id "af1uLARrcwUCjTCAmIXZMwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
YF
2026-05-08 04:31:03
(1 month ago)
Git config exposure probe
Web App Attack
Anonymous
2026-05-08 04:00:05
(1 month ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 03:59:38
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 23:59:32.516374 2026] [security2:error] [pid 17285:tid 17285] [client 34.146.252.145:42860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "echelonts.com.demondomain.com"] [uri "/.git/config"] [unique_id "af1fpMfpUp5Z92FLET6MeQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 03:19:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 23:19:39.981037 2026] [security2:error] [pid 27045:tid 27048] [client 34.146.252.145:51696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "playerintro.beckmon.com"] [uri "/.git/config"] [unique_id "af1WS71WrNsOav_zs197QwAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-08 03:18:44
(1 month ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 02:39:45
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.252.145 (145.252.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 22:39:38.558150 2026] [security2:error] [pid 23536:tid 23536] [client 34.146.252.145:54012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fydelity.net"] [uri "/.git/config"] [unique_id "af1M6oA6EA7VzWsxd5a5MQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack