๐ซ๐ฎ
YF
2026-08-26 20:00:45
(55 minutes ago)
Git config exposure probe
Web App Attack
๐ฌ๐ง
consul.to
2026-08-26 19:12:31
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 18:59:58
(1 hour ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
webko.si
2026-08-26 18:42:24
(2 hours ago)
BARUTANA.si: Bruteforce web app access, URI detail: '/.git/config'.
Web App Attack
๐บ๐ธ
araptus
2026-08-26 18:29:12
(2 hours ago)
Gateway auto-report: /.git/config (UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36)
Web App Attack
Hacking
๐ซ๐ท
pm33
2026-08-26 18:17:14
(2 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
Anonymous
2026-08-26 17:35:21
(3 hours ago)
apache vulnerability scan
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 17:28:56
(3 hours ago)
cloudlinux2 fail2ban: 2026-08-26 19:23:49,060 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-26 19:23:49,060 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 136.244.91.143 - 2026-08-26 19:23:48cloudlinux2 fail2ban: 2026-08-26 19:23:59,859 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.197.142.114 - 2026-08-26 19:23:59cloudlinux2 fail2ban: 2026-08-26 19:24:05,775 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 41.235.177.212 - 2026-08-26 19:24:05cloudlinux2 fail2ban: 2026-08-26 19:24:16,999 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 41.235.177.212 - 2026-08-26 19:24:16cloudlinux2 fail2ban: 2026-08-26 19:24:17,354 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Ban 41.235.177.212cloudlinux2 fail2ban: 2026-08-26 19:24:17,360 fail2ban.filter [1775]: INFO [recidive] Found 41.235.177.212 - 2026-08-26 19:24:17cloudlinux2 fail2ban: 2026-08-26 19:24:27,754 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 104.199.165.58 - 2026-08-26 19:24:27cloudlinux2 fail2ban: 2
show less
Web App Attack
๐บ๐ธ
abenage
2026-08-26 17:25:52
(3 hours ago)
34.170.6.80 - - [26/Aug/2026:11:25:51 -0600] "x16x03x01x00xE8x01x00x00xE4x03x03x9DxFExF4xFBx19xC8x80 ...
show more
34.170.6.80 - - [26/Aug/2026:11:25:51 -0600] "x16x03x01x00xE8x01x00x00xE4x03x03x9DxFExF4xFBx19xC8x80xA2x90x88xF2xECx90ax8CG[x9CxD6x05xE5xBF]F,2xD4'Hx1DxCCxE4 /,xEAxD6x9CxB1Pz'x92xF0FCxCCxAExDEx1CDIxA7x15(x90xC8xB9x15xD6x1Ax84xA9xAFx07x00x14x13x02x13x01x13x03xC0,xC0+xCCxA9xC00xC0/xCCxA8x00xFFx01x00x00x87x00-x00x02x01x01x00x17x00x00x00#x00x00x00x05x00x05x01x00x00x00x00x003x00&x00$x00x1Dx00 x89=x83xEF/@xAAxDFDxB0x0EG@x9ExDExEBxCE!x9C}x84xBAx17cxC7( x84ex8Cx13x1Fx00" 400 166 "-" "-"
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:48:53
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:48:47.389438 2026] [security2:error] [pid 31274:tid 31274] [client 34.170.6.80:38484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoticus.com"] [uri "/.git/config"] [unique_id "ao7Ej4KB30Ed8N4m_Big3AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:15:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:15:26.854978 2026] [security2:error] [pid 32038:tid 32055] [client 34.170.6.80:58800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulvester.com"] [uri "/.git/config"] [unique_id "ao68vnUwG2A5dkgyDXcvkwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-26 10:15:27
(10 hours ago)
[Wed Aug 26 20:15:26.845320 2026] [security2:error] [pid 361283] [client 34.170.6.80:2134] [client 3 ...
show more
[Wed Aug 26 20:15:26.845320 2026] [security2:error] [pid 361283] [client 34.170.6.80:2134] [client 34.170.6.80] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.com.au"] [uri "/.git/config"] [unique_id "ao68vm8rjYhBr5SyPq0fAAAAAAc"]
...
show less
Web App Attack
Anonymous
2026-08-26 09:22:46
(11 hours ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 05:19:57
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:19:49.266890 2026] [security2:error] [pid 12377:tid 12377] [client 34.170.6.80:14896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morivercloggers.com"] [uri "/.env"] [unique_id "ao53daBr6XGRIaY3Sz1BcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 04:44:37
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.170.6.80 (80.6.170.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 00:44:31.214544 2026] [security2:error] [pid 15501:tid 15501] [client 34.170.6.80:35618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "morganmotors.com"] [uri "/.env"] [unique_id "ao5vL6aiwKMTLT1ajuyESQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack