๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(2 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-09-17 03:34:47
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐ต๐ฑ
Budyn
2026-09-17 03:31:19
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-17 02:13:49
(6 hours ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (BE/AS396982)
Web App Attack
Hacking
Anonymous
2026-09-16 20:17:32
(12 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:53:45
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:53:07.047372 2026] [security2:error] [pid 16059:tid 16059] [client 34.53.248.248:59548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rkhindustries.com"] [uri "/.git/config"] [unique_id "aqqRM_51vGBrcAuC4pT_nwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:13:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:13:45.760866 2026] [security2:error] [pid 20357:tid 20357] [client 34.53.248.248:43576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailorbandido.com"] [uri "/.git/config"] [unique_id "aqpPuRNoo5a9TYeJaI3iiwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:51:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:51:03.852440 2026] [security2:error] [pid 7208:tid 7208] [client 34.53.248.248:51290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailingcharterburma.com"] [uri "/.git/config"] [unique_id "aqpKZ-79ijtg6Q76Z3QEBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:32:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.248.248 (248.248.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:31:54.236172 2026] [security2:error] [pid 27962:tid 27969] [client 34.53.248.248:34666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sailcleaner.com"] [uri "/.git/config"] [unique_id "aqpF6neP9FourQEkKXX0SwAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 07:14:26
(1 day ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.53.248.248 - - \[16/Sep/2026:09:14:10 +0200\] "GET /.git/config HTTP/1.1" 301 620 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-16 06:45:13
(1 day ago)
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 05:53:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-16 07:50:02,281 fail2ban.actions [1818]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 07:50:02,281 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 34.40.27.223cloudlinux2 fail2ban: 2026-09-16 07:50:32,328 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 34.18.135.64cloudlinux2 fail2ban: 2026-09-16 07:50:36,243 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 45.132.227.104 - 2026-09-16 07:50:35cloudlinux2 fail2ban: 2026-09-16 07:51:01,605 fail2ban.filter [1818]: INFO [plesk-proftpd] Found 207.180.248.207 - 2026-09-16 07:51:01cloudlinux2 fail2ban: 2026-09-16 07:51:05,575 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Unban 113.185.86.162cloudlinux2 fail2ban: 2026-09-16 07:51:12,773 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 185.142.40.80 - 2026-09-16 07:51:11cloudlinux2 fail2ban: 2026-09-16 07:51:47,386 fail2ban.filter [1818]: INFO [plesk-wordpress] Found 193.37.33.181 - 2026-09-16 07:51:46cloudlinux2 fail2ban: 2026-09-16 07:52:31,707 fail2ban.filter
show less
FTP Brute-Force
Web App Attack
Anonymous
2026-09-16 04:40:28
(1 day ago)
2026/09/16 06:40:26 [error] 2433724#2433724: *2281 access forbidden by rule, client: 34.53.248.248, ...
show more
2026/09/16 06:40:26 [error] 2433724#2433724: *2281 access forbidden by rule, client: 34.53.248.248, server: sahpa.co.za, request: "GET /.git/config HTTP/1.1", host: "sahpa.co.za"
2026/09/16 06:40:27 [error] 2433724#2433724: *2281 access forbidden by rule, client: 34.53.248.248, server: sahpa.co.za, request: "GET /.env HTTP/1.1", host: "sahpa.co.za"
2026/09/16 06:40:27 [error] 2433724#2433724: *2281 access forbidden by rule, client: 34.53.248.248, server: sahpa.co.za, request: "GET /.env.local HTTP/1.1", host: "sahpa.co.za"
...
show less
Hacking
Web App Attack
Anonymous
2026-09-16 03:41:12
(1 day ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-16 03:34:02
(1 day ago)
Bad behaviour
Web Spam