🇮🇳
evicky2002
2026-09-14 06:00:01
(4 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇵🇱
Budyn
2026-09-14 00:47:23
(9 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: p.budyn.wtf | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-14 00:44:10
(9 hours ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.57.202.231 - - \[14/Sep/2026:02:44:09 +0200\] "GET /.git/config HTTP/1.1" 301 5776 "-" "-"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 00:41:41
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 20:41:35.794105 2026] [security2:error] [pid 4956:tid 4956] [client 34.57.202.231:58308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pbeyer.org"] [uri "/.git/config"] [unique_id "aqdCv-07A2K6Y90Vt-RPuAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
librebit
2026-09-14 00:23:34
(10 hours ago)
Brute force
Brute-Force
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-14 00:08:10
(10 hours ago)
34.57.202.231 - - [13/Sep/2026:18:08:09 -0600] "GET /.git/config HTTP/1.1" 300 8020 "-" "-"
...
Web App Attack
Anonymous
2026-09-13 23:46:00
(10 hours ago)
Web application attack detected.
Web App Attack
🇩🇪
FeG Deutschland
2026-09-13 23:38:57
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 23:38:38
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 19:38:34.482025 2026] [security2:error] [pid 7687:tid 7687] [client 34.57.202.231:48194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pawzy-app.com.lucid-events.com"] [uri "/.git/config"] [unique_id "aqcz-rh57jhbb-MYeZMBLwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Roper123
2026-09-13 23:33:00
(11 hours ago)
Web exploits
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-13 23:24:31
(11 hours ago)
[Mon Sep 14 09:24:30.596866 2026] [security2:error] [pid 36627] [client 34.57.202.231:49244] [client ...
show more
[Mon Sep 14 09:24:30.596866 2026] [security2:error] [pid 36627] [client 34.57.202.231:49244] [client 34.57.202.231] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/.git/config"] [unique_id "aqcwrgAagxuSRlhi7lrRLQAAAAc"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 23:16:06
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.202.231 (231.202.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 19:16:02.832386 2026] [security2:error] [pid 21184:tid 21184] [client 34.57.202.231:60478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulaperez.com"] [uri "/.git/config"] [unique_id "aqcuskCQrC5ehpdproc7MQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 23:10:29
(11 hours ago)
34.57.202.231 patrz.eu - [14/Sep/2026:01:10:27 +0200] "GET /.git/config HTTP/1.1" 418 709 "-" "-"
.. ...
show more
34.57.202.231 patrz.eu - [14/Sep/2026:01:10:27 +0200] "GET /.git/config HTTP/1.1" 418 709 "-" "-"
...
show less
Hacking
Web App Attack
🇩🇪
Vegascosmetics
2026-09-13 23:10:15
(11 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇵🇱
sefinek.net
2026-09-13 23:10:01
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Empty string • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot