Anonymous
2026-09-04 11:12:50
(6 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.inradis.com; logs=/var/log/httpd/domains/inradis.com.lo ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.inradis.com; logs=/var/log/httpd/domains/inradis.com.log; samples=/app/.git/config | /src/.git/config | /public/.git/config
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 07:08:11
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:20:18
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:20:13.537582 2026] [security2:error] [pid 15249:tid 15249] [client 35.229.212.161:51900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.norbertesser.com"] [uri "/src/.git/config"] [unique_id "appjHco4S2a1ntBbewg_YgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:55:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:54:52.471659 2026] [security2:error] [pid 2001:tid 2001] [client 35.229.212.161:58422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.auditleverage.com"] [uri "/www/.git/config"] [unique_id "appPHLuxw2vCA9fBvngO3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
FreeMyIP
2026-09-04 02:36:10
(14 hours ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 02:28:56
(14 hours ago)
cloudlinux2 fail2ban: 2026-09-04 04:24:45,527 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 04:24:45,527 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.80.218.173 - 2026-09-04 04:24:45cloudlinux2 fail2ban: 2026-09-04 04:24:44,579 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 193.19.109.116 - 2026-09-04 04:24:43cloudlinux2 fail2ban: 2026-09-04 04:24:46,242 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 193.19.109.147 - 2026-09-04 04:24:43cloudlinux2 fail2ban: 2026-09-04 04:24:53,125 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 188.137.234.248 - 2026-09-04 04:24:52cloudlinux2 fail2ban: 2026-09-04 04:26:23,417 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.212.161 - 2026-09-04 04:26:23cloudlinux2 fail2ban: 2026-09-04 04:26:23,444 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.212.161 - 2026-09-04 04:26:23cloudlinux2 fail2ban: 2026-09-04 04:26:23,425 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.212.161 - 2026-09-04 04
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:27:27
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:27:22.942444 2026] [security2:error] [pid 8277:tid 8277] [client 35.229.212.161:50674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixitz.net"] [uri "/www/.git/config"] [unique_id "apoQamK9ebIl6Ubb5PWSbwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 00:04:05
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 23:42:33
(17 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Vegascosmetics
2026-09-03 23:03:17
(18 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇩🇪
Séfora Srl
2026-09-03 22:50:10
(18 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
🇳🇴
jad-abuse
2026-09-03 20:14:33
(21 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 36 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:08:02
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.212.161 (161.212.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:07:57.949613 2026] [security2:error] [pid 1098:tid 1098] [client 35.229.212.161:44504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelpmcgrath.com"] [uri "/app/.git/config"] [unique_id "apnFjcwv9vyKBfLaUaTzCwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 18:58:56
(22 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
raph
2026-09-03 18:01:29
(23 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack