๐ณ๐ฑ
homeshowdomain.nl
2026-07-29 21:59:53
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-28.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-29 07:00:00
(1 day ago)
Automated Apache web application probing in selected 24h window; attempts=46, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=46, unique_paths=1, error_responses=33; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=46; exact paths: /.git/config
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-28 21:59:10
(1 day ago)
Auto-ban: >3000 req/min op 2026-07-28
Web App Attack
SSH
Hacking
๐ฎ๐น
Inartis
2026-07-28 19:53:08
(1 day ago)
35.223.54.120 - - [28/Jul/2026:21:53:07 +0200] "GET /.git/config HTTP/1.1" 200 54705 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 19:34:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 15:34:42.434619 2026] [security2:error] [pid 1833890:tid 1833890] [client 35.223.54.120:57590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trompelart.com"] [uri "/.git/config"] [unique_id "amkEUuvVPtuosg74kWt35gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-28 19:25:02
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ง๐ฌ
pa4080
2026-07-28 19:08:11
(1 day ago)
Detected by ModSecurity. Request URI: /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:59:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:59:30.231896 2026] [security2:error] [pid 2606483:tid 2606483] [client 35.223.54.120:36530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tristarus.com"] [uri "/.git/config"] [unique_id "amj8ElIr5bDg_Le0KPUwkgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-28 18:48:29
(1 day ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.223.54.120 - - [28/Jul/2026:21:48:29 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.223.54.120 - - [28/Jul/2026:21:48:29 +0300] "GET /.git/config HTTP/1.1" 403 6276 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:41:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:40:54.277926 2026] [security2:error] [pid 2467309:tid 2467309] [client 35.223.54.120:54682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tripeak.llc"] [uri "/.git/config"] [unique_id "amj3tg4kak0QWg5r3s0gWQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 18:32:54
(1 day ago)
2026/07/28 16:08:20 [error] 4730#4730: *215811 [client 35.223.54.120] ModSecurity: Access denied wit ...
show more
2026/07/28 16:08:20 [error] 4730#4730: *215811 [client 35.223.54.120] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.28.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "traveltrack.logiciensoft.com"] [uri "/.git/config"] [unique_id "178525490032.491282"] [ref ""], client: 35.223.54.120, server: srv.ingeltechgh.com, request: "GET /.git/config HTTP/1.1", host: "traveltrack.logiciensoft.com"
2026/07/28 18:31:35 [error] 2656751#2656751: *218299 [client 35.223.54.120] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-28 18:22:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.54.120 (120.54.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:22:13.449788 2026] [security2:error] [pid 26700:tid 26700] [client 35.223.54.120:37474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trilliantsolutions.com"] [uri "/.git/config"] [unique_id "amjzVYIyol8CxGPf3QAxHwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-28 18:14:48
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
Oakley
2026-07-28 18:11:58
(1 day ago)
(confirmed_bot_sig) Confirmed bot
Hacking