๐ฎ๐ณ
evicky2002
2026-07-14 10:21:11
(2 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐ณ
evicky2002
2026-07-09 06:00:00
(3 months ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐จ๐ญ
TheCoon
2026-05-16 19:15:01
(4 months ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ฉ๐ช
wicked.design
2026-05-15 12:35:00
(4 months ago)
Abusive web request for automated exploitation.
Brute-Force
Web App Attack
๐ซ๐ท
geot
2026-05-15 12:16:16
(4 months ago)
GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐น๐ผ
tye
2026-05-15 07:29:23
(4 months ago)
Wazuh Alert Evidence: [Fri May 15 15:29:19.998609 2026] [security2:error] [pid 3473078] [client 35.1 ...
show more
Wazuh Alert Evidence: [Fri May 15 15:29:19.998609 2026] [security2:error] [pid 3473078] [client 35.199.115.51:37232] [client 35.199.115.51] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/apache2/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.23.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "www.tye.asia"] [uri "/.git/config"] [unique_id "agbLT1tlZCpNbW7KJe4pEQAAAAI"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 07:17:22
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 03:17:13.820485 2026] [security2:error] [pid 32580:tid 32580] [client 35.199.115.51:50388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abeolson.flyingdodostudio.com"] [uri "/.git/config"] [unique_id "agbIefgFy2dEUy9LQhJhqQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-15 06:13:33
(4 months ago)
[FriMay1508:13:30.2031782026][security2:error][pid3879966:tid3880275][client35.199.115.51:0]ModSecur ...
show more
[FriMay1508:13:30.2031782026][security2:error][pid3879966:tid3880275][client35.199.115.51:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-web-hosting.ch\"][uri\"/.git/config\"][unique_id\"aga5ip6PEQJVgaM08oCc5QAAARU\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 05:57:11
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 01:57:04.195614 2026] [security2:error] [pid 24967:tid 24967] [client 35.199.115.51:58716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skyfall-estate.com"] [uri "/.git/config"] [unique_id "aga1sN2uDf8ME_I_5UJcRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 05:29:17
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 01:29:09.354812 2026] [security2:error] [pid 24760:tid 24760] [client 35.199.115.51:55336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unionega.com"] [uri "/.git/config"] [unique_id "agavJdib6YViT7cx1FBh-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-05-15 05:18:01
(4 months ago)
Automated recon attempt targeting restricted and sensitive paths.
Web App Attack
Anonymous
2026-05-15 04:56:10
(4 months ago)
Banned by Fail2Ban on server
Bad Web Bot
Anonymous
2026-05-15 04:56:03
(4 months ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 04:17:56
(4 months ago)
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.115.51 (51.115.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 00:17:51.572196 2026] [security2:error] [pid 18195:tid 18195] [client 35.199.115.51:49948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pleasanthillfarms.com"] [uri "/.git/config"] [unique_id "agaeb_gwPEeZK6emLbhncgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2026-05-15 04:09:54
(4 months ago)
Wordpress malicious attack:[octablocked]
Web App Attack