๐ฉ๐ช
dbmwebdesign
2026-09-24 09:15:08
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-24 05:16:53
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:34:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:34:15.732631 2026] [security2:error] [pid 7156:tid 7156] [client 34.39.113.230:40986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cressyvideo.com"] [uri "/api/.git/config"] [unique_id "arSoR16gDz-HIPldf9RpnQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:28:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:28:24.896934 2026] [security2:error] [pid 25656:tid 25656] [client 34.39.113.230:39654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.perlcreative.com"] [uri "/src/.git/config"] [unique_id "arSKyOZuJg3aE9p-hnosqgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:43:31
(4 days ago)
527 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 21:07:55
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:07:50.402613 2026] [security2:error] [pid 29842:tid 29842] [client 34.39.113.230:47404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clipper1970.com"] [uri "/html/.git/config"] [unique_id "arQ_ps7cOZh7tD8M5xW77gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
arcy
2026-09-23 19:20:31
(4 days ago)
Detected by CrowdSec IDS on a self-hosted server. Target: HTTP/HTTPS (ports 80/443). Triggered rules ...
show more
Detected by CrowdSec IDS on a self-hosted server. Target: HTTP/HTTPS (ports 80/443). Triggered rules: http-sensitive-files. 5 matching log events at 2026-09-23T19:20:31Z (UTC). Sample requests: GET /html/.git/config -> 200; GET /api/.git/config -> 404; GET /var/www/.git/config -> 200; GET /public/.git/config -> 200; GET /wordpress/.git/config -> 200
show less
Hacking
Web App Attack
Anonymous
2026-09-23 17:55:02
(4 days ago)
suspicious request in access.log
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 17:06:40
(4 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:42:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:42:21.196341 2026] [security2:error] [pid 31694:tid 31694] [client 34.39.113.230:58956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brandfacets.com"] [uri "/htdocs/.git/config"] [unique_id "arPlTQpqlIAKZQGymRSnzQAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 14:03:39
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-23 13:48:40
(4 days ago)
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /wordpress/ ...
show more
[ssd5.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /wordpress/.git/config | /site/.git/config
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:33:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.113.230 (230.113.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:33:28.790557 2026] [security2:error] [pid 30012:tid 30012] [client 34.39.113.230:37066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bipocmentalhealthcoalition.org"] [uri "/html/.git/config"] [unique_id "arPHGF8diShMG1_BhFInDgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 11:38:40
(4 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 11:16:03
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack