πΏπ¦
conure.sh
2026-10-06 12:08:46
(19 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in -1s
Web App Attack
π¬π§
openstrike.co.uk
2026-10-06 05:13:42
(1 day ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-10-06 04:17:23
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
π§π·
radardatelecom
2026-10-05 22:27:04
(1 day ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-05 21:46:39
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 21:30:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:30:46.963258 2026] [security2:error] [pid 21524:tid 21524] [client 34.172.85.167:36074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vendor21.com"] [uri "/.git/config"] [unique_id "asQXBoe_NRKRj5HEw0REdQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-10-05 21:28:52
(1 day ago)
2.706 requests with url.path */.git/config
992 requests with url.path *.git/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-05 21:10:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 17:10:41.765851 2026] [security2:error] [pid 26875:tid 26875] [client 34.172.85.167:50994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velocity40.com"] [uri "/.git/config"] [unique_id "asQSURazjO3c5zdDVnG5sAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
j-tap
2026-10-05 21:05:35
(1 day ago)
WordPress honeypot: automated scanner (xmlrpc / installer / .env / direct login POST)
Web App Attack
π©πͺ
FeG Deutschland
2026-10-05 21:01:52
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 20:34:06
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.172.85.167 (167.85.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.172.85.167 (167.85.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:34:03.153584 2026] [security2:error] [pid 581:tid 581] [client 34.172.85.167:42690] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "vdeweese.com"] [uri "/.git/config"] [unique_id "asQJuwCKMQpcwIrLDgWSLQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 20:08:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:08:12.853160 2026] [security2:error] [pid 7395:tid 7395] [client 34.172.85.167:33880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vc1.com"] [uri "/.git/config"] [unique_id "asQDrPrkboOEbMezg3fTxQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
infra-monitor
2026-10-05 20:00:04
(1 day ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
π¦πΊ
Bay13
2026-10-05 19:47:19
(1 day ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 19:35:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.85.167 (167.85.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 15:35:28.988098 2026] [security2:error] [pid 652386:tid 652395] [client 34.172.85.167:34872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vavryn.net"] [uri "/.git/config"] [unique_id "asP8AJllK4Vdb5lpEfRiowAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack