๐ฎ๐ณ
evicky2002
2026-07-30 06:00:00
(22 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-07-30 05:13:57
(22 hours ago)
3 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-07-29 23:05:36
(1 day ago)
Portscan: TCP/443 (6x)
Port Scan
๐ฌ๐ง
Aetherweb Ark
2026-07-29 22:00:56
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.9.250.245 (US/United States/245.250.9.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.9.250.245 (US/United States/245.250.9.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
Charlesiv
2026-07-29 22:00:19
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-07-29T20:50:56Z
Ray ID: a22effb18b0e6071
UA: Empty string
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-29 21:40:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:40:12.454742 2026] [security2:error] [pid 3924807:tid 3924807] [client 34.9.250.245:58766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thalos.pe"] [uri "/.git/config"] [unique_id "ampzPHhWXtPd9xzjHAC9EwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-29 21:38:36
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 34.9.250.245 - - [30/Jul/2026:00:38:36 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 34.9.250.245 - - [30/Jul/2026:00:38:36 +0300] "GET /.git/config HTTP/1.1" 403 6273 "-" "-"
show less
Web App Attack
๐น๐ญ
thaizone.com
2026-07-29 21:37:53
(1 day ago)
Brute Force Attack on a Web Resources (probe) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐ณ๐ฑ
prinsbert
2026-07-29 21:14:43
(1 day ago)
Hit honeypot route /.git/config
Web App Attack
Anonymous
2026-07-29 21:07:01
(1 day ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-07-29 20:45:44.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 21:06:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 17:06:10.880338 2026] [security2:error] [pid 2991567:tid 2991567] [client 34.9.250.245:46736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tgaguide.com"] [uri "/.git/config"] [unique_id "amprQlwDXM1yq_95FBEJZAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 20:25:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:25:30.378424 2026] [security2:error] [pid 2291426:tid 2291426] [client 34.9.250.245:47078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "texascottagebakers.org.texascottagebakers.com"] [uri "/.git/config"] [unique_id "amphupFLk5XYO1PzPksk1wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 20:13:57
(1 day ago)
cloudlinux2 fail2ban: 2026-07-29 22:08:53,020 fail2ban.filter [1584]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-29 22:08:53,020 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 192.250.239.107 - 2026-07-29 22:08:52cloudlinux2 fail2ban: 2026-07-29 22:09:13,188 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.146.55.87 - 2026-07-29 22:09:12cloudlinux2 fail2ban: 2026-07-29 22:09:09,772 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.146.55.87 - 2026-07-29 22:09:08cloudlinux2 fail2ban: 2026-07-29 22:09:11,268 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.146.55.73 - 2026-07-29 22:09:10cloudlinux2 fail2ban: 2026-07-29 22:10:15,371 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 139.59.102.237 - 2026-07-29 22:10:15cloudlinux2 fail2ban: 2026-07-29 22:10:28,129 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 34.9.250.245 - 2026-07-29 22:10:28cloudlinux2 fail2ban: 2026-07-29 22:11:01,229 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.131.193.118 - 2026-07-29 22:11:00cloudli
show less
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-29 20:08:09
(1 day ago)
IM360 WAF: Direct access to sensitive file or dotfile MV:/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 20:06:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.250.245 (245.250.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:06:34.436499 2026] [security2:error] [pid 216839:tid 216839] [client 34.9.250.245:48418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "test.zeta-me.com"] [uri "/.git/config"] [unique_id "ampdSmgD-f_2TPfN4nmJqQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack