๐ณ๐ด
jad-abuse
2026-07-26 08:14:33
(15 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 276 hits.
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-07-26 06:28:41
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 06:01:44
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:01:40.754612 2026] [security2:error] [pid 2608711:tid 2608711] [client 34.243.244.213:60226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fedeoliva.com"] [uri "/.git/config"] [unique_id "amWixOeVH7yVBD4MOp8e1QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
febrian.de
2026-07-26 02:42:52
(21 hours ago)
Malicious HTTP(S) probing detected by Fail2Ban
Web App Attack
๐ฉ๐ช
4server
2026-07-24 11:06:16
(2 days ago)
[FriJul2413:06:13.7295432026][security2:error][pid2771133:tid2771481][client34.243.244.213:0]ModSecu ...
show more
[FriJul2413:06:13.7295432026][security2:error][pid2771133:tid2771481][client34.243.244.213:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"agenziastella.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"amNHJYuUfqLBB2JDD-bYnwAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:38:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:38:17.839013 2026] [security2:error] [pid 4014825:tid 4014825] [client 34.243.244.213:48702] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agenesis7.com"] [uri "/.git/config"] [unique_id "amMkeY_ZqYnpxq2dyfTiGgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 07:19:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:19:36.084854 2026] [security2:error] [pid 3543251:tid 3543251] [client 34.243.244.213:40222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ageh.com"] [uri "/.git/config"] [unique_id "amMSCGyzdjwigamaypeGEAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 06:45:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:26:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:26:50.638411 2026] [security2:error] [pid 3948311:tid 3948311] [client 34.243.244.213:35006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agapeaccounting.com"] [uri "/.git/config"] [unique_id "amMFqjxRNAaYiEM8Rke1wAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 04:42:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.243.244.213 (ec2-34-243-244-213.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:42:17.672043 2026] [security2:error] [pid 1626664:tid 1626664] [client 34.243.244.213:48748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afscmelocal2794.com"] [uri "/.git/config"] [unique_id "amLtKZKwb7PRgqBKdmWOwwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 03:08:01
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
afleventoffice.com.au
2026-07-23 16:56:19
(3 days ago)
GET /.git/config HTTP/1.1
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-15 03:53:33
(1 month ago)
IM360 WAF: Block system file path in request MV:/etc/passwd
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-03 07:39:44
(1 month ago)
IM360 WAF: System Command Access
Hacking
๐ฑ๐ป
garmtech.com
2026-06-03 07:39:44
(1 month ago)
IM360 WAF: Injection of Undocumented ColdFusion Tags (CVE-2023-44350)
Web App Attack