๐ฌ๐ง
consul.to
2026-08-06 08:45:09
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-06 07:35:25
(2 weeks ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
4server
2026-08-06 04:03:53
(2 weeks ago)
[ThuAug0606:03:51.1458552026][security2:error][pid3522936:tid3523003][client34.17.159.73:0]ModSecuri ...
show more
[ThuAug0606:03:51.1458552026][security2:error][pid3522936:tid3523003][client34.17.159.73:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"titancapital.ch\"][uri\"/wordpress/.git/config\"][unique_id\"anQHpwXni3JE9hq-fsd3cQAAAEo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ญ
4server
2026-08-06 03:43:34
(2 weeks ago)
[ThuAug0605:43:27.7282472026][security2:error][pid4140967:tid4141251][client34.17.159.73:0]ModSecuri ...
show more
[ThuAug0605:43:27.7282472026][security2:error][pid4140967:tid4141251][client34.17.159.73:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"annunci-ticino.ch\"][uri\"/app/.git/config\"][unique_id\"anQC3yK_3Ap-0pCs0Gd-yQAAAMI\"]
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-08-06 01:48:59
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sinus.budyn.wtf | URI: /.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-08-05 18:30:45
(2 weeks ago)
malicious bot detected: violations="hit-honeypot"; user_agent="crusader-worker/1.0"
Web App Attack
๐บ๐ธ
kosada.com
2026-08-05 17:27:05
(2 weeks ago)
Web vulnerability probing: /app/.git/config
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-05 15:26:21
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ช
Ivo Vynckier
2026-08-05 14:58:00
(2 weeks ago)
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 157 "-" "cru ...
show more
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /api/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /www/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /backend/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /app/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /src/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.17.159.73 - - [05/Aug/2026:03:26:42 +0200] "GET /.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
Matthew Ping
2026-08-05 09:00:01
(2 weeks ago)
ModSecurity rule 949110 triggered on server. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐จ๐ฆ
polycoda
2026-08-05 06:39:46
(2 weeks ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-08-05 04:31:50
(2 weeks ago)
552 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-08-05 03:08:32
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-05 00:17:07
(2 weeks ago)
2026/08/04 21:17:06 [error] 3747385#3747385: *156115 access forbidden by rule, client: 34.17.159.73, ...
show more
2026/08/04 21:17:06 [error] 3747385#3747385: *156115 access forbidden by rule, client: 34.17.159.73, server: guiadovarejo.com.br, request: "GET /api/.git/config HTTP/1.1", host: "www.guiadovarejo.com.br"
2026/08/04 21:17:06 [error] 3747387#3747387: *156114 access forbidden by rule, client: 34.17.159.73, server: guiadovarejo.com.br, request: "GET /htdocs/.git/config HTTP/1.1", host: "www.guiadovarejo.com.br"
2026/08/04 21:17:06 [error] 3747387#3747387: *156113 access forbidden by rule, client: 34.17.159.73, server: guiadovarejo.com.br, request: "GET /html/.git/config HTTP/1.1", host: "www.guiadovarejo.com.br"
...
show less
Port Scan
๐ณ๐ฑ
Eric
2026-08-04 21:21:23
(2 weeks ago)
[Tue Aug 04 21:21:22.676209 2026] [security2:error] [pid 4084657:tid 4084657] [client 34.17.159.73:5 ...
show more
[Tue Aug 04 21:21:22.676209 2026] [security2:error] [pid 4084657:tid 4084657] [client 34.17.159.73:50204] [client 34.17.159.73] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "anJX0rHbfmXupBg4WXhQlAAAAAs"]
[Tue Aug 04 21:21:22.676754 2026] [security2:error] [pid 4084657:tid 4084657] [client 34.17.159.73:50204] [client 34.17.159.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
Hacking
Web App Attack