Anonymous
2026-09-25 22:38:37
(37 minutes ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-25 12:02:56
(11 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in -1s
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-25 06:30:52
(16 hours ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config. Blocked ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-09-25 05:14:38
(18 hours ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ซ๐ท
service Informatique
2026-09-25 04:00:37
(19 hours ago)
/.git
Web App Attack
๐ง๐ช
cmbplf
2026-09-25 01:01:20
(22 hours ago)
341 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-25 00:32:27
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 20:32:21.777666 2026] [security2:error] [pid 1189:tid 1189] [client 35.199.5.143:59312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noscentpro.com"] [uri "/.git/config"] [unique_id "arXBFWW_kGoLc-aRnkjvGAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 22:27:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 18:27:13.703445 2026] [security2:error] [pid 9181:tid 9181] [client 35.199.5.143:55492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northstar-village.org"] [uri "/.git/config"] [unique_id "arWjwT0em_x1vQRqg-DpqAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-24 22:00:28
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 21:58:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:58:07.441903 2026] [security2:error] [pid 29296:tid 29296] [client 35.199.5.143:50700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northfultonneurology.com"] [uri "/.git/config"] [unique_id "arWc76VZEOC1qlK9p_1dSQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 21:37:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:37:33.815556 2026] [security2:error] [pid 8120:tid 8120] [client 35.199.5.143:49032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "northamericantrucking.com"] [uri "/.git/config"] [unique_id "arWYHXzujx9ceueoFX9EjgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-24 21:37:10
(1 day ago)
Repeated exploit attempts, for example: /.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 21:22:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.5.143 (143.5.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 17:22:25.551282 2026] [security2:error] [pid 12969:tid 12969] [client 35.199.5.143:52072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "norinpaco.com"] [uri "/.git/config"] [unique_id "arWUkQQ5zeHOGkc4KH4aWwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
abuseiphack
2026-09-24 21:12:09
(1 day ago)
Automatic report for brute force attack
Web App Attack
๐บ๐ธ
mnsf
2026-09-24 21:05:18
(1 day ago)
Scanning/Probing (11)
Brute-Force
Web App Attack