๐ณ๐ด
jad-abuse
2026-09-20 20:12:29
(12 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-20 20:07:43
(17 minutes ago)
cloudlinux2 fail2ban: 2026-09-20 21:58:41,447 fail2ban.filter [1597]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-20 21:58:41,447 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 35.203.30.201 - 2026-09-20 21:58:41cloudlinux2 fail2ban: 2026-09-20 21:58:41,539 fail2ban.actions [1597]: NOTICE [plesk-modsecurity] Ban 35.203.30.201cloudlinux2 fail2ban: 2026-09-20 21:58:41,340 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 35.203.30.201 - 2026-09-20 21:58:41cloudlinux2 fail2ban: 2026-09-20 21:58:41,231 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 35.203.30.201 - 2026-09-20 21:58:41cloudlinux2 fail2ban: 2026-09-20 21:58:41,556 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 35.203.30.201 - 2026-09-20 21:58:41cloudlinux2 fail2ban: 2026-09-20 21:58:46,859 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 34.90.243.201 - 2026-09-20 21:58:46cloudlinux2 fail2ban: 2026-09-20 21:58:41,546 fail2ban.filter [1597]: INFO [recidive] Found 35.203.30.201 - 2026-09-20 21:58:41cloudlinux2 fail2ban: 2026-0
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:59:12
(25 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:59:08.191799 2026] [security2:error] [pid 16641:tid 16641] [client 34.90.243.201:33858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.frickandfracks.com"] [uri "/.git/config"] [unique_id "arA7DE_Qba3LiuAAkuv-7AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-20 19:48:12
(36 minutes ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:41:10
(43 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:41:07.056085 2026] [security2:error] [pid 24634:tid 24634] [client 34.90.243.201:33932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.freightmotivity.com"] [uri "/.git/config"] [unique_id "arA20xCMC0I0zHns9i_afgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MM-bot
2026-09-20 19:32:09
(52 minutes ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-09-20 21:32:09 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
shadowgaming
2026-09-20 19:25:05
(59 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Empty string โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ธ๐ช
SkyDancer
2026-09-20 19:22:46
(1 hour ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-20 19:22:17
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 34.90.243.201 (201.243.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.90.243.201 (201.243.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:22:09.352335 2026] [security2:error] [pid 10590:tid 10590] [client 34.90.243.201:33028] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.freedrm.org"] [uri "/.git/config"] [unique_id "arAyYVs7qa5Ujxy7vBNiDQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-20 18:54:41
(1 hour ago)
34.90.243.201 - - [20/Sep/2026:20:54:38 +0200] "GET /.git/config HTTP/1.1" 404 5197 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 18:40:03
(1 hour ago)
suspicious request in access.log
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 18:06:20
(2 hours ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 18:04:21
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:02:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.90.243.201 (201.243.90.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:02:26.932979 2026] [security2:error] [pid 5400:tid 5400] [client 34.90.243.201:46026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magiccarpentry.com.citystreetsalon.com"] [uri "/.git/config"] [unique_id "arAfsqZlfHEoqKZdRicflwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-20 17:41:26
(2 hours ago)
Login credentials theft attempt
Hacking