๐ฎ๐ณ
evicky2002
2026-05-14 06:00:00
(1 month ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-05-10 22:00:33
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-09.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
itabu
2026-05-10 05:00:17
(1 month ago)
Malicious web scanner/bot detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 03:30:36
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 23:30:29.382512 2026] [security2:error] [pid 3395:tid 3395] [client 34.17.129.224:52824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sipa.com.hk"] [uri "/.git/config"] [unique_id "af_71bOz_OcNCoXtVjqs2QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
NotACaptcha
2026-05-10 03:20:01
(1 month ago)
webserver:443 [10/May/2026] "GET /.git/config HTTP/1.1" 403 4156 "-" "Mozilla/5.0 (compatible; Yand ...
show more
webserver:443 [10/May/2026] "GET /.git/config HTTP/1.1" 403 4156 "-" "Mozilla/5.0 (compatible; YandexBot/3.0; +http://yandex.com/bots)"
show less
Web App Attack
๐ซ๐ท
masterguru
2026-05-10 02:48:32
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.17.129.224 (IT/Italy/224.129.17.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.17.129.224 (IT/Italy/224.129.17.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ง๐ช
cmbplf
2026-05-10 01:49:04
(1 month ago)
561 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐ฌ๐ง
andypiper
2026-05-10 01:02:47
(1 month ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 00:48:52
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 20:48:46.404854 2026] [security2:error] [pid 19902:tid 19902] [client 34.17.129.224:51436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "digitalmarketing-group.com"] [uri "/.git/config"] [unique_id "af_V7icnoNOrKvG_5yx82wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 00:10:44
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 20:10:40.872045 2026] [security2:error] [pid 16204:tid 16204] [client 34.17.129.224:57546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlecreekrvranch.com"] [uri "/.git/config"] [unique_id "af_NAHyAoMhLLcdTaRsnHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-09 23:48:02
(1 month ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 23:47:51
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 19:47:44.511026 2026] [security2:error] [pid 8084:tid 8084] [client 34.17.129.224:56790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrcd.org"] [uri "/.git/config"] [unique_id "af_HoLlLkrpTiQWXJjCT1AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-05-09 23:34:47
(1 month ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 23:23:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.129.224 (224.129.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 19:23:05.194103 2026] [security2:error] [pid 22526:tid 22526] [client 34.17.129.224:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.abdulhameeds.art"] [uri "/.git/config"] [unique_id "af_B2ct4VZQ4hKMH4MhPUAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-09 23:12:47
(1 month ago)
Unauthorized access to webpage admin
Web App Attack