๐ซ๐ฎ
payincog
2026-08-24 16:00:32
(2 days ago)
Date: Aug 24 18:23:56 2026 EAT | Reported IP: 34.80.41.72 mod_security | id: 930130 949110 | TW/pay. ...
show more
Date: Aug 24 18:23:56 2026 EAT | Reported IP: 34.80.41.72 mod_security | id: 930130 949110 | TW/pay.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; Restricted File Access Attempt; Restricted File Access Attempt; Inbound Anomaly Score Exceeded (Total Score: 5); Inbound Anomaly Score Exceeded (Total Score: 5)
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฆ๐ช
CG
2026-08-24 15:58:21
(2 days ago)
Web application attack, Automated scan
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
CBJ
2026-08-24 15:36:02
(2 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
RamSet
2026-08-24 15:28:41
(2 days ago)
[swy] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 21s. Sustained 2 req/min. Path ...
show more
[swy] HTTP-Probe on port 443 (via domain). 1 distinct paths probed in 21s. Sustained 2 req/min. Paths: /.git/config
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:23:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:23:53.120834 2026] [security2:error] [pid 27184:tid 27184] [client 34.80.41.72:11236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dubb.productions"] [uri "/.git/config"] [unique_id "aoxiCYWE-jYyfzOU7ETMvgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ผ
tye
2026-08-24 15:21:40
(2 days ago)
Wazuh Alert Evidence: 34.80.41.72 (34.80.41.72) - - [24/Aug/2026:23:21:36 +0800] "GET /.git/config H ...
show more
Wazuh Alert Evidence: 34.80.41.72 (34.80.41.72) - - [24/Aug/2026:23:21:36 +0800] "GET /.git/config HTTP/1.1" 404 5188 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
๐บ๐ธ
cwytech
2026-08-24 15:21:26
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:00:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:00:01.985082 2026] [security2:error] [pid 2188:tid 2188] [client 34.80.41.72:29300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepferlab.org"] [uri "/.git/config"] [unique_id "aoxccVqMp_UydECg_Qj5EgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 13:33:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:33:49.882548 2026] [security2:error] [pid 26458:tid 26458] [client 34.80.41.72:2212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hbgmccormickfoundation.org"] [uri "/.git/config"] [unique_id "aoxIPUicx3KdAidSYyPzeAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 12:53:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:53:44.959623 2026] [security2:error] [pid 11456:tid 11456] [client 34.80.41.72:54138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfarmersmarkets.org"] [uri "/.git/config"] [unique_id "aow-2LNz8MLD1zsh3x66oQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 12:36:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.41.72 (72.41.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:36:29.487708 2026] [security2:error] [pid 19901:tid 19901] [client 34.80.41.72:43870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edlee.biz"] [uri "/.git/config"] [unique_id "aow6zWEBS9LSK3eazkUrqgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-24 12:22:08
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.xyz | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-24 11:59:20
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
nate naten
2026-08-24 11:33:25
(2 days ago)
HoneyTrap: git_config attempt on /.git/config from Taiwan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-04-19 14:26:03
(4 months ago)
categories: Email Spam
Email Spam