🇨🇭
Ribeye375
2026-09-04 22:59:17
(11 hours ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack
🇷🇴
iulianh
2026-09-04 22:54:45
(11 hours ago)
80,443
Brute-Force
SSH
🇮🇹
ciccio diddo
2026-09-04 22:33:57
(11 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:56:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:56:20.955864 2026] [security2:error] [pid 30881:tid 30908] [client 34.72.198.98:57024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.koalacogs.com"] [uri "/html/.git/config"] [unique_id "aps-hPE1t-41Fnyico237wAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 21:47:35
(12 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 18:05:34
(16 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-04 14:26:23
(19 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: u.budyn.wtf | URI: /.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:28:06
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:28:00.315908 2026] [security2:error] [pid 5381:tid 5381] [client 34.72.198.98:58244] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rambleandprose.com"] [uri "/backend/.git/config"] [unique_id "apq5UP_4JfS96jnw3fgcXgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Spider
2026-09-04 10:18:40
(23 hours ago)
Automated report from Atlas Development (atlas-development.net) edge protection. Systematic path enu ...
show more
Automated report from Atlas Development (atlas-development.net) edge protection. Systematic path enumeration detected: 3 distinct endpoints probed within 10 minutes, cycling through common CMS install-path guesses. Sample: GET /var/www/.git/config (404) GET /app/.git/config (404) GET /backend/.git/config (404)
show less
Bad Web Bot
Web App Attack
🇬🇧
blik2108
2026-09-04 09:50:29
(1 day ago)
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /api/.git/config HTTP/1.1" 404 153 "-" "crusader- ...
show more
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /api/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /app/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /src/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /www/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /var/www/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /htdocs/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
34.72.198.98 - - [04/Sep/2026:09:50:26 +0000] "GET /wordpress/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0" "-"
...
show less
Web App Attack
Anonymous
2026-09-04 09:05:01
(1 day ago)
suspicious request in access.log
Web App Attack
🇧🇪
voormedia
2026-09-04 08:05:08
(1 day ago)
Accessed trap at '/.git/config'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:26:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:26:33.073846 2026] [security2:error] [pid 11194:tid 11194] [client 34.72.198.98:39976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scoutinsignia.com"] [uri "/backend/.git/config"] [unique_id "appyqSg3zfT_L6PfytQGFgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-09-04 06:04:38
(1 day ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-04 05:30:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.72.198.98 (98.198.72.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:30:00.971627 2026] [security2:error] [pid 32254:tid 32254] [client 34.72.198.98:36804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.greensandbeans.us"] [uri "/api/.git/config"] [unique_id "appXWGx_EZvVbL5loSCZFwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack