๐บ๐ธ
TPI-Abuse
2026-09-16 07:51:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.235.160 (160.235.154.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.235.160 (160.235.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:51:00.923429 2026] [security2:error] [pid 7208:tid 7208] [client 34.154.235.160:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.nyemdr.org"] [uri "/.git/config"] [unique_id "aqpKZO79ijtg6Q76Z3QD_wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-09-15 22:03:53
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-09-15 18:39:03
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 18:24:09
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 09:21:39
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-09-15 09:17:15
(1 day ago)
2026/09/15 11:17:14 [error] 6102#100732: *6490296 access forbidden by rule, client: 34.154.235.160, ...
show more
2026/09/15 11:17:14 [error] 6102#100732: *6490296 access forbidden by rule, client: 34.154.235.160, server: new.hondaforum.hu, request: "GET / HTTP/1.1", host: "new.hondaforum.hu"
...
show less
Web Spam
๐ฎ๐ณ
evicky2002
2026-09-13 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=90, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Little Iguana
2026-09-12 10:59:55
(4 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ต๐ฑ
nfsec.pl
2026-08-29 21:12:05
(2 weeks ago)
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /api/.git/config HTTP/1.1" 403 357 "-" "crusade ...
show more
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /api/.git/config HTTP/1.1" 403 357 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /wordpress/.git/config HTTP/1.1" 403 357 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /www/.git/config HTTP/1.1" 403 357 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /backend/.git/config HTTP/1.1" 403 357 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:21:12:04 +0000] "GET /app/.git/config HTTP/1.1" 403 357 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Exploited Host
๐ฉ๐ช
ghostwarriors
2026-08-29 18:50:08
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ซ๐ฎ
oh.mg
2026-08-29 13:35:40
(2 weeks ago)
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 2312 "-" "cru ...
show more
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 2312 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /public/.git/config HTTP/1.1" 403 943 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /www/.git/config HTTP/1.1" 403 2312 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /html/.git/config HTTP/1.1" 403 2312 "-" "crusader-worker/1.0"
34.154.235.160 - - [29/Aug/2026:15:35:39 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 2312 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
simon boshoff
2026-08-29 12:04:26
(2 weeks ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ณ๐ฑ
0xffffffff
2026-08-29 09:39:10
(2 weeks ago)
[2026-08-29 12:39:08.698713] [authz_core:error] [pid 2380712:tid 127818075690688] [client 34.154.235 ...
show more
[2026-08-29 12:39:08.698713] [authz_core:error] [pid 2380712:tid 127818075690688] [client 34.154.235.160:55506] AH01630: client denied by server configuration: /var/www/*/htdocs , error_notes:config-files , URI:'/htdocs/.git/config'
[2026-08-29 12:39:08.702383] [authz_core:error] [pid 2380713:tid 127818245637824] [client 34.154.235.160:55446] AH01630: client denied by server configuration: /var/www/*/backend , error_notes:config-files , URI:'/backend/.git/config'
[2026-08-29 12:39:08.704157] [authz_core:error] [pid 2380713:tid 127818262423232] [client 34.154.235.160:55464] AH01630: client denied by server configuration: /var/www/*/www , error_notes:config-files , URI:'/www/.git/config'
[2026-08-29 12:39:08.716933] [authz_core:error] [pid 2380713:tid 127818117654208] [client 34.154.235.160:55436] AH01630: client denied by server configuration: /var/www/*/app , error_notes:config-files , URI:'/app/.git/config'
[2026-08-29 12:39:08.718260] [authz_core:error] [pid 2380713:tid 127817572390592] [client 34.154.235.1
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-29 04:41:39
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:06:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.154.235.160 (160.235.154.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.235.160 (160.235.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:06:26.082723 2026] [security2:error] [pid 29267:tid 29267] [client 34.154.235.160:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.swarnar.com"] [uri "/.git/config"] [unique_id "apJMsifkhC4h0QnYJFhLiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack