🇩🇪
ghostwarriors
2026-09-05 08:50:06
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-05 05:13:50
(5 hours ago)
12 attacks on VC URLs:
GET /backend/.git/config HTTP/1.1
Hacking
Anonymous
2026-09-05 01:23:22
(9 hours ago)
Web Attack Gitscanner Traffic Detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:57:57
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:57:50.759506 2026] [security2:error] [pid 7051:tid 7051] [client 35.200.126.114:56650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lisarlee.com"] [uri "/backend/.git/config"] [unique_id "aps-3pMS2jjUfSRW8CcdpQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 21:45:07
(12 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-04 21:15:17
(13 hours ago)
80,443
Brute-Force
SSH
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:15:13
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:11:35
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:11:31.368323 2026] [security2:error] [pid 21088:tid 21088] [client 35.200.126.114:50184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fibw.com"] [uri "/site/.git/config"] [unique_id "aps0A3nMiAxMAF4J90SoJgAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 21:06:40
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 20:18:25
(14 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇨🇭
ALPHANET
2026-09-04 19:40:10
(14 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:07:53
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:07:46.362555 2026] [security2:error] [pid 28243:tid 28243] [client 35.200.126.114:57614] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "toxicnation.org"] [uri "/src/.git/config"] [unique_id "apsI8hfYMwx0x3gZ5LrdlQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
gadix
2026-09-04 16:57:53
(17 hours ago)
[04/Sep/2026:18:57:50.817709 +0200] apr4jvJWYBaeIJF8HJ0V9QAAAAE 35.200.126.114 44520 127.0.0.1 7081
...
show more
[04/Sep/2026:18:57:50.817709 +0200] apr4jvJWYBaeIJF8HJ0V9QAAAAE 35.200.126.114 44520 127.0.0.1 7081
[04/Sep/2026:18:57:50.819910 +0200] apr4jqvLKKXsaa_BwQgcEgAAABU 35.200.126.114 44532 127.0.0.1 7081
[04/Sep/2026:18:57:50.825358 +0200] apr4jpoz3euaoGBd5lNZ7wAAABc 35.200.126.114 44548 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:46:34
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:46:27.505204 2026] [security2:error] [pid 21322:tid 21322] [client 35.200.126.114:44376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crucialpins.com"] [uri "/var/www/.git/config"] [unique_id "aprn07gY_ke_8yaYDe1j5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:54:33
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.126.114 (114.126.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:29.183668 2026] [security2:error] [pid 19835:tid 19835] [client 35.200.126.114:54194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jerniganbuilders.com"] [uri "/.git/config"] [unique_id "apqxdYmWsR5ueQb_YSsBwwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack