Anonymous
2026-09-22 16:36:51
(37 minutes ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
craudiovizai
2026-09-22 12:30:49
(4 hours ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config. Blocked ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-22 12:04:51
(5 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐น
[email protected]
2026-09-21 22:52:45
(18 hours ago)
34.27.202.201 - - [21/Sep/2026:21:39:36 +0200] "GET /.git/config HTTP/1.1" 404 5424 "-" "-"
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 21:28:06
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:28:03.076356 2026] [security2:error] [pid 26824:tid 26824] [client 34.27.202.201:36016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnedwardsconsulting.com"] [uri "/.git/config"] [unique_id "arGhY84EiI6m4TlPGPWzigAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:57:33
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:57:28.345650 2026] [security2:error] [pid 26166:tid 26166] [client 34.27.202.201:39846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryhetrick.com"] [uri "/.git/config"] [unique_id "arGaONp4Wsw_Hk6Of4qf-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-21 20:54:39
(20 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.astropot.website | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:34:58
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:34:54.182797 2026] [security2:error] [pid 19703:tid 19703] [client 34.27.202.201:56970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamesclarklaw.com"] [uri "/.git/config"] [unique_id "arGU7ipGZWR79cG3PW7eEQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:14:52
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:14:46.626547 2026] [security2:error] [pid 31904:tid 31904] [client 34.27.202.201:40728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "itre.org"] [uri "/.git/config"] [unique_id "arGQNtDDZvP051HccJ5aHAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:54:56
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.202.201 (201.202.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:54:51.605595 2026] [security2:error] [pid 22228:tid 22228] [client 34.27.202.201:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.atlascoombs.com"] [uri "/.git/config"] [unique_id "arGLi_3sdh7iqtY2go_IBgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-21 19:54:27
(21 hours ago)
Login credentials theft attempt
Hacking
๐ณ๐ฑ
ipoac.nl
2026-09-21 19:52:55
(21 hours ago)
ipoac.nl:443 34.27.202.201 - - [21/Sep/2026:21:52:53 +0200] ipoac.nl "GET /.git/config HTTP/1.1" 403 ...
show more
ipoac.nl:443 34.27.202.201 - - [21/Sep/2026:21:52:53 +0200] ipoac.nl "GET /.git/config HTTP/1.1" 403 6355 "-" "-"
show less
Bad Web Bot
๐ฉ๐ช
IVski.com
2026-09-21 19:52:38
(21 hours ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
sternwart
2026-09-21 19:51:22
(21 hours ago)
Automatisch erkannt: Zugriff auf /.git/config (ipa.ready4future.ch)
Web App Attack
Bad Web Bot