๐ต๐ฑ
Budyn
2026-09-21 16:54:43
(6 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cpanel.teddypot.tech | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-09-21 16:44:06
(17 minutes ago)
2026-09-21 16:43:54 GET /.git/config - - 34.158.42.192 HTTP/1.1 - - 301 851
...
Brute-Force
Web App Attack
Anonymous
2026-09-21 16:34:53
(26 minutes ago)
Scanner hitting /.git/config on ppbn.osef.cloud (GOOGL-2) โ aaguard
Brute-Force
Port Scan
๐ณ๐ด
jad-abuse
2026-09-21 15:56:43
(1 hour ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:23:36
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:23:32.360026 2026] [security2:error] [pid 28529:tid 28529] [client 34.158.42.192:36336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "suffe.cool"] [uri "/.git/config"] [unique_id "arFL9JxcVmWgIV7fa2wZRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:18:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:18:30.885832 2026] [security2:error] [pid 9773:tid 9786] [client 34.158.42.192:51666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catapultpt.com"] [uri "/.git/config"] [unique_id "arE8tuQTzkLohTzNUjodJAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:50:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:50:23.587765 2026] [security2:error] [pid 12154:tid 12154] [client 34.158.42.192:46394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "spiralingmedia.com"] [uri "/.git/config"] [unique_id "arE2H90V--X_MR2Wzq8cBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 10:07:55
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:07:49.553082 2026] [security2:error] [pid 13925:tid 13925] [client 34.158.42.192:39766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stukabird.com"] [uri "/.git/config"] [unique_id "arEB9V9zAi1I6wekQPjhoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 09:53:56
(7 hours ago)
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CR ...
show more
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 09:40:06
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 05:39:58.836592 2026] [security2:error] [pid 22561:tid 22561] [client 34.158.42.192:52222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zabyte.net"] [uri "/.git/config"] [unique_id "arD7bp0Gmt6ITCksvT-SogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 09:09:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.42.192 (192.42.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 05:09:10.904234 2026] [security2:error] [pid 19767:tid 19767] [client 34.158.42.192:33790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tarakanov.com"] [uri "/.git/config"] [unique_id "arD0NtAPLUohDAw0fTct3QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 09:03:56
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-21 10:59:14,368 fail2ban.actions [1598]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 10:59:14,368 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 35.246.60.207cloudlinux2 fail2ban: 2026-09-21 11:00:31,153 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.92.198.176 - 2026-09-21 11:00:27cloudlinux2 fail2ban: 2026-09-21 11:00:35,394 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.198.241.51 - 2026-09-21 11:00:35cloudlinux2 fail2ban: 2026-09-21 11:00:44,956 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 134.209.3.91 - 2026-09-21 11:00:44cloudlinux2 fail2ban: 2026-09-21 11:00:45,905 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 134.209.3.91 - 2026-09-21 11:00:44cloudlinux2 fail2ban: 2026-09-21 11:00:42,512 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.158.42.192 - 2026-09-21 11:00:42cloudlinux2 fail2ban: 2026-09-21 11:00:48,430 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.81.122.163 - 2026-09-21 11:00:48cloudlinux2 fail2ban: 2
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-21 08:18:22
(8 hours ago)
Try to access /.git/config
Web App Attack
Anonymous
2026-09-21 07:15:02
(9 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 07:05:38
(9 hours ago)
Abuse Detected (13)
Brute-Force
Web App Attack