🇦🇹
Starburst SysOp Team
2026-08-28 16:44:31
(1 week ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-vie6-1)
Hacking
Web App Attack
🇮🇹
mediarama.com
2026-08-28 14:18:38
(1 week ago)
Banned by Fail2Ban
Web App Attack
Anonymous
2026-08-28 14:13:39
(1 week ago)
Excessive 404 errors - web scanning/probing
Bad Web Bot
🇩🇪
Vegascosmetics
2026-08-28 14:12:31
(1 week ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
stinpriza
2026-08-28 11:10:57
(1 week ago)
common Web Exploits being scanned
Web App Attack
🇩🇪
patrisei
2026-08-28 10:51:17
(1 week ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-27 22:01:19
(1 week ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
🇩🇪
Teufel100
2026-08-27 12:22:03
(2 weeks ago)
Bruteforce gegen Einstellungsdateien wie .env oder .git
Brute-Force
Hacking
Web App Attack
🇺🇸
Gabriel Camargo
2026-08-27 11:04:19
(2 weeks ago)
35.186.158.188 - - [27/Aug/2026:06:04:18 -0500] "GET /var/www/.git/config HTTP/1.1" 301 178 "-" "cru ...
show more
35.186.158.188 - - [27/Aug/2026:06:04:18 -0500] "GET /var/www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.186.158.188 - - [27/Aug/2026:06:04:18 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
35.186.158.188 - - [27/Aug/2026:06:04:18 -0500] "GET /site/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇮🇹
CoreTech srl
2026-08-27 10:08:56
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-27 12:03:49,591 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-27 12:03:49,591 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 167.71.35.238 - 2026-08-27 12:03:49cloudlinux2 fail2ban: 2026-08-27 12:04:34,384 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27 12:04:33cloudlinux2 fail2ban: 2026-08-27 12:04:34,318 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27 12:04:33cloudlinux2 fail2ban: 2026-08-27 12:04:34,334 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27 12:04:33cloudlinux2 fail2ban: 2026-08-27 12:04:34,367 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27 12:04:33cloudlinux2 fail2ban: 2026-08-27 12:04:34,326 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27 12:04:33cloudlinux2 fail2ban: 2026-08-27 12:04:34,351 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.186.158.188 - 2026-08-27
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 08:47:59
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:47:53.692155 2026] [security2:error] [pid 9889:tid 9999] [client 35.186.158.188:46828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.projectmanagementcertification.org"] [uri "/public/.git/config"] [unique_id "ao_5uRVk5uy3XO5Sffl3aAAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 06:53:00
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:52:56.163959 2026] [security2:error] [pid 12833:tid 12833] [client 35.186.158.188:60320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kistner.us"] [uri "/backend/.git/config"] [unique_id "ao_eyC3kNGWjHaLQp8Vd2AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 06:11:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.186.158.188 (188.158.186.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:11:00.467634 2026] [security2:error] [pid 17537:tid 17537] [client 35.186.158.188:52956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jonnyonthespot.biz"] [uri "/src/.git/config"] [unique_id "ao_U9FTSK6GucgoKr4acvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-27 05:25:08
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-08-27 05:05:23
(2 weeks ago)
Scanning/Probing (12)
Brute-Force
Web App Attack