๐ฎ๐ณ
evicky2002
2026-05-20 04:30:47
(3 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-05-09 21:59:28
(4 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-08.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
Gertec
2026-05-08 11:22:48
(4 months ago)
This IP address 34.165.33.143 has been carrying out attacks on our website. Reason: Blocked IP addre ...
show more
This IP address 34.165.33.143 has been carrying out attacks on our website. Reason: Blocked IP address | Method: GET | Path: /.git/config.
show less
Hacking
DDoS Attack
๐บ๐ธ
mnsf
2026-05-08 09:06:48
(4 months ago)
Too many Status 40X (11)
Scanning/Probing (21)
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-05-08 07:29:20
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.165.33.143 (IL/Israel/143.33.165 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.165.33.143 (IL/Israel/143.33.165.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ท๐บ
Mga Admin
2026-05-08 07:01:23
(4 months ago)
34.165.33.143 - - [08/May/2026:14:01:22 +0700] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
34.165.33.143 - - [08/May/2026:14:01:22 +0700] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 9; SAMSUNG SM-G975U1 Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/9.4 Chrome/67.0.3396.87 Mobile Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 05:19:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 01:19:33.774800 2026] [security2:error] [pid 4618:tid 4618] [client 34.165.33.143:45838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ask2023.com.whatifandwhynot.xyz"] [uri "/.git/config"] [unique_id "af1yZV9SxHUz_Eo59GD9kwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 04:24:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 08 00:24:36.930770 2026] [security2:error] [pid 10700:tid 10700] [client 34.165.33.143:56074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mail.zmgmt.com"] [uri "/.git/config"] [unique_id "af1lhCSpPZd5WEqGbreKSwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 02:15:24
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 22:15:21.290113 2026] [security2:error] [pid 13821:tid 13821] [client 34.165.33.143:60790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jfhglobal.haworthconsultinggroup.com"] [uri "/.git/config"] [unique_id "af1HOTB_5jq-oxQNE228hQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bescared
2026-05-08 01:54:33
(4 months ago)
F2B - Malicious activity detected. URL Probing. -8ff06ede-
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-05-08 01:34:43
(4 months ago)
34.165.33.143 - - [08/May/2026:01:34:42 +0000] "GET /.git/config HTTP/1.1" 404 19663 "-" "Mozilla/5. ...
show more
34.165.33.143 - - [08/May/2026:01:34:42 +0000] "GET /.git/config HTTP/1.1" 404 19663 "-" "Mozilla/5.0 (Linux; Android 8.1.0; ZB602KL) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-08 01:24:41
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 21:24:36.641560 2026] [security2:error] [pid 9234:tid 9234] [client 34.165.33.143:37330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b2c-llc.anthonyanimalclinic.net"] [uri "/.git/config"] [unique_id "af07VCYKNPmgz7zRPJSSPQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-08 00:49:38
(4 months ago)
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints ( ...
show more
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-08 00:45:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 20:45:35.567377 2026] [security2:error] [pid 31324:tid 31324] [client 34.165.33.143:38516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.katemcleod.kathrynmcbride.com"] [uri "/.git/config"] [unique_id "af0yL9RkhWfWUtuPmbX7egAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-07 23:47:39
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.33.143 (143.33.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 19:47:35.114551 2026] [security2:error] [pid 11829:tid 11829] [client 34.165.33.143:56256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.skintormint.com"] [uri "/.git/config"] [unique_id "af0klw_bi603nK0QW1vj6wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack