๐ง๐ช
cmbplf
2026-08-22 11:46:52
(2 hours ago)
101 requests with url.path *.hg/*
Brute-Force
Bad Web Bot
๐ท๐ด
clauss
2026-08-22 09:29:31
(4 hours ago)
34.67.180.3 - - [22/Aug/2026:12:29:29 +0300] "GET /.DS_Store HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windo ...
show more
34.67.180.3 - - [22/Aug/2026:12:29:29 +0300] "GET /.DS_Store HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
34.67.180.3 - - [22/Aug/2026:12:29:30 +0300] "GET /.DS_Store HTTP/2.0" 404 10291 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-08-22 09:13:18
(5 hours ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 08:43:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 04:43:52.963321 2026] [security2:error] [pid 21816:tid 21816] [client 34.67.180.3:51974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.connectigramme.com"] [uri "/.git/HEAD"] [unique_id "aolhSLlDdX48_3TIklclzgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
miriks
2026-08-22 08:00:29
(6 hours ago)
Automated scan detected: GET /.git/HEAD โ UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/ ...
show more
Automated scan detected: GET /.git/HEAD โ UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-22 07:28:51
(6 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.67.180.3 (US/United States/3.180 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.67.180.3 (US/United States/3.180.67.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
elcruzado.es
2026-08-22 07:04:35
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.67.180.3 (US/United States/3.180.67. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.67.180.3 (US/United States/3.180.67.34.bc.googleusercontent.com)
show less
SQL Injection
๐ต๐ฑ
Budyn
2026-08-22 06:55:01
(7 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: app.goblinpot.online | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 06:25:41
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:25:36.096834 2026] [security2:error] [pid 15059:tid 15059] [client 34.67.180.3:36094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jacksonlimobus.com"] [uri "/.git/HEAD"] [unique_id "aolA4AiOfdxFzqY4wM8tSQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-22 06:15:22
(8 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 06:06:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:06:36.842989 2026] [security2:error] [pid 18798:tid 18798] [client 34.67.180.3:36478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ahuramazda.com"] [uri "/.git/HEAD"] [unique_id "aok8bJHlz29PDcCbenHr7AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 05:29:29
(8 hours ago)
[Sat Aug 22 05:29:26.840796 2026] [authz_core:error] [pid 979667:tid 979667] [client 34.67.180.3:369 ...
show more
[Sat Aug 22 05:29:26.840796 2026] [authz_core:error] [pid 979667:tid 979667] [client 34.67.180.3:36920] AH01630: client denied by server configuration: /var/www/erp.gassycat.co.uk/htdocs/.git
[Sat Aug 22 05:29:27.224421 2026] [authz_core:error] [pid 979675:tid 979675] [client 34.67.180.3:36922] AH01630: client denied by server configuration: /var/www/erp.gassycat.co.uk/htdocs/.git
[Sat Aug 22 05:29:27.608307 2026] [authz_core:error] [pid 979710:tid 979710] [client 34.67.180.3:36924] AH01630: client denied by server configuration: /var/www/erp.gassycat.co.uk/htdocs/.svn
[Sat Aug 22 05:29:28.028497 2026] [authz_core:error] [pid 979673:tid 979673] [client 34.67.180.3:36938] AH01630: client denied by server configuration: /var/www/erp.gassycat.co.uk/htdocs/.svn
[Sat Aug 22 05:29:28.414636 2026] [authz_core:error] [pid 979672:tid 979672] [client 34.67.180.3:36952] AH01630: client denied by server configuration: /var/www/erp.gassycat.co.uk/htdocs/CVS
...
show less
Brute-Force
Anonymous
2026-08-22 05:07:02
(9 hours ago)
Automated web scanner. Requested suspicious paths: /.git/HEAD. UTC: 2026-08-22 04:47:23.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 04:49:40
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.180.3 (3.180.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 00:49:32.691916 2026] [security2:error] [pid 4948:tid 4948] [client 34.67.180.3:49652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidocchino.com"] [uri "/.git/HEAD"] [unique_id "aokqXG1uklek7f3oTYphQAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-08-22 04:15:02
(10 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack