🇸🇪
SkyDancer
2026-09-04 10:41:21
(3 hours ago)
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by ...
show more
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai via interface.
show less
Hacking
Brute-Force
SSH
🇸🇪
SkyDancer
2026-09-04 06:48:22
(7 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇫🇷
masterguru
2026-09-04 02:08:48
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇫🇷
Stara
2026-09-04 01:24:20
(12 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇩🇪
febrian.de
2026-09-04 00:53:19
(13 hours ago)
Excessive HTTP(S) probing or bad web bot detected by Fail2Ban
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:45:28
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:45:23.003611 2026] [security2:error] [pid 31156:tid 31173] [client 34.153.194.116:38878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spam.absurdotron.com"] [uri "/wordpress/.git/config"] [unique_id "apoGk7Xaduj_y9pQpykr5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-03 20:21:00
(17 hours ago)
34.153.194.116 - - [03/Sep/2026:15:21:00 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusade ...
show more
34.153.194.116 - - [03/Sep/2026:15:21:00 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.153.194.116 - - [03/Sep/2026:15:21:00 -0500] "GET /www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.153.194.116 - - [03/Sep/2026:15:21:00 -0500] "GET /backend/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-03 16:27:19
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:27:12.548675 2026] [security2:error] [pid 1809:tid 1809] [client 34.153.194.116:60708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.joseluisperez.com"] [uri "/src/.git/config"] [unique_id "apmf4JFKxCoc-lVkK8i4LAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
LiloBzH
2026-09-03 15:30:54
(22 hours ago)
34.153.194.116 - - [03/Sep/2026:17:30:52 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-wo ...
show more
34.153.194.116 - - [03/Sep/2026:17:30:52 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.153.194.116 - - [03/Sep/2026:17:30:52 +0200] "GET /backend/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.153.194.116 - - [03/Sep/2026:17:30:52 +0200] "GET /api/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:28:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:28:23.610543 2026] [security2:error] [pid 8497:tid 8497] [client 34.153.194.116:53752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffolksystems.com"] [uri "/app/.git/config"] [unique_id "apl196ljwlsdGGeZcvvPtQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-09-03 10:00:05
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇮🇹
VHosting
2026-09-03 09:55:06
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 09:48:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:47:54.412952 2026] [security2:error] [pid 12020:tid 12020] [client 34.153.194.116:48218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.amtnm.com"] [uri "/api/.git/config"] [unique_id "aplCShr0qp-JCqoGjuK47wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
afleventoffice.com.au
2026-09-03 06:36:27
(1 day ago)
GET /htdocs/.git/config HTTP/1.1
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:51:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.153.194.116 (116.194.153.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:51:51.745869 2026] [security2:error] [pid 22103:tid 22103] [client 34.153.194.116:34310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "1writeforthegrant.growtowork.com"] [uri "/.git/config"] [unique_id "apkK92UXIXSEQ9WMpykzCwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack