๐ฎ๐ณ
evicky2002
2026-07-21 06:00:00
(16 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-07-21 05:14:20
(17 hours ago)
4 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ซ๐ท
Magnytu2
2026-07-20 23:32:04
(23 hours ago)
hoe-17 : Block hidden directories=>/.git/config(/)
Hacking
Anonymous
2026-07-20 23:23:16
(23 hours ago)
File repository snooping:
34.80.9.75 - - [21/Jul/2026:00:23:16 +0100] "GET /.git/config HTTP/1.1" 4 ...
show more
File repository snooping:
34.80.9.75 - - [21/Jul/2026:00:23:16 +0100] "GET /.git/config HTTP/1.1" 404 234 "-" "Unknown"
show less
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-20 23:08:57
(23 hours ago)
cloudlinux2 fail2ban: 2026-07-21 01:05:25,369 fail2ban.filter [1927]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-21 01:05:25,369 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 34.80.9.75 - 2026-07-21 01:05:25cloudlinux2 fail2ban: 2026-07-21 01:05:41,464 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 216.73.163.144 - 2026-07-21 01:05:40cloudlinux2 fail2ban: 2026-07-21 01:05:41,395 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 216.73.163.154 - 2026-07-21 01:05:40cloudlinux2 fail2ban: 2026-07-21 01:06:07,913 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.36.224.224 - 2026-07-21 01:06:07cloudlinux2 fail2ban: 2026-07-21 01:06:08,850 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.36.224.243 - 2026-07-21 01:06:07cloudlinux2 fail2ban: 2026-07-21 01:07:14,103 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 172.202.30.101 - 2026-07-21 01:07:14cloudlinux2 fail2ban: 2026-07-21 01:07:19,014 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Unban 34.118.2.237cloudlinux2 fail2ban: 20
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 22:12:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 18:12:11.268371 2026] [security2:error] [pid 32276:tid 32276] [client 34.80.9.75:56334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fydelity.net"] [uri "/.git/config"] [unique_id "al6dO64AjbG-MJ0oDzNGLgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-20 21:43:24
(1 day ago)
[Tue Jul 21 07:43:23.516981 2026] [security2:error] [pid 155192] [client 34.80.9.75:57842] [client 3 ...
show more
[Tue Jul 21 07:43:23.516981 2026] [security2:error] [pid 155192] [client 34.80.9.75:57842] [client 34.80.9.75] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.furst.com.au"] [uri "/.git/config"] [unique_id "al6We9m0LESiTE_X_tlpAgAAAAI"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 21:00:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 17:00:32.878907 2026] [security2:error] [pid 15458:tid 15458] [client 34.80.9.75:33996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fuji.cloudex.link"] [uri "/.git/config"] [unique_id "al6McB-7Cp2WQinpoJwpsQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Magnytu2
2026-07-20 20:27:16
(1 day ago)
fse-17 : Block hidden directories=>/.git/config(/)
Hacking
Anonymous
2026-07-20 20:16:46
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ซ๐ท
JPPO
2026-07-20 20:12:59
(1 day ago)
Port 443 : GET /.git or /.git/HEAD, /.git/config ... /.DS_store
Web App Attack
Anonymous
2026-07-20 20:09:07
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-20 20:08:57
(1 day ago)
cloudlinux2 fail2ban: 2026-07-20 22:03:59,992 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-20 22:03:59,992 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 136.144.33.244 - 2026-07-20 22:03:59cloudlinux2 fail2ban: 2026-07-20 22:04:29,862 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 156.67.31.167 - 2026-07-20 22:04:29cloudlinux2 fail2ban: 2026-07-20 22:05:00,078 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 136.144.33.244 - 2026-07-20 22:04:59cloudlinux2 fail2ban: 2026-07-20 22:05:53,230 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 216.73.160.36 - 2026-07-20 22:05:52cloudlinux2 fail2ban: 2026-07-20 22:05:57,922 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 216.73.160.36 - 2026-07-20 22:05:57cloudlinux2 fail2ban: 2026-07-20 22:05:57,719 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 34.80.9.75 - 2026-07-20 22:05:57cloudlinux2 fail2ban: 2026-07-20 22:05:57,922 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 216.73.160.39 - 2026-07-20 22:05:57cloudlin
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 19:48:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.9.75 (75.9.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 15:48:20.225910 2026] [security2:error] [pid 11523:tid 11523] [client 34.80.9.75:55450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frickandfracks.com"] [uri "/.git/config"] [unique_id "al57hM_wrIWoei6OlvCzJgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-20 19:37:52
(1 day ago)
csagent: score 17.9: secrets grab x2, 404 noise floor x2; 2 domain(s) in 51s
Web App Attack