๐ฌ๐ง
andypiper
2026-08-23 01:02:26
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-23 00:11:09
(2 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.229.54.52 - - [21/Aug/2026:18:37:29 +0300] "GE ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.229.54.52 - - [21/Aug/2026:18:37:29 +0300] "GET /.git/config HTTP/1.1" 404 808 "-" "-"
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-22 22:04:23
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-21.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-08-22 12:03:30
(2 days ago)
csagent: score 20.0: secrets grab x2, 404 noise floor x2; 2 domain(s) in 9s
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-22 05:15:07
(3 days ago)
3 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-21 22:50:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 18:50:17.894156 2026] [security2:error] [pid 3579:tid 3579] [client 35.229.54.52:48510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drxcontent.com"] [uri "/.git/config"] [unique_id "aojWKV-0Ylq8p_rvTnlY_gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 22:15:47
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 18:15:41.491282 2026] [security2:error] [pid 29328:tid 29328] [client 35.229.54.52:44076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drrw.net"] [uri "/.git/config"] [unique_id "aojODfHLSv0U_GDfxZrt8QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-21 22:03:56
(3 days ago)
Auto-ban: >3000 req/min op 2026-08-21
Web App Attack
SSH
Hacking
๐บ๐ธ
Charlesiv
2026-08-21 22:01:49
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-08-21T21:30:12Z
Ray ID: a2ecbcd30ffd1a67
UA: Empty string
show less
Bad Web Bot
๐ฉ๐ฐ
ScamAware
2026-08-21 22:00:32
(3 days ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ฉ๐ช
tsZero
2026-08-21 21:38:17
(3 days ago)
Scan example: path=/.git/config status=404
Hacking
๐บ๐ธ
Epimetheus
2026-08-21 21:32:20
(3 days ago)
Unauthorized access attempts:
[GET] /.git/config
UA: Unknown
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:16:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:16:38.210736 2026] [security2:error] [pid 10595:tid 10595] [client 35.229.54.52:57158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drhasanunal.chevronparkett.com"] [uri "/.git/config"] [unique_id "aojANiZ0h5TMTmAQTTPFRAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 20:40:49
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:40:42.390242 2026] [security2:error] [pid 11224:tid 11224] [client 35.229.54.52:41896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbbenefits.com"] [uri "/.git/config"] [unique_id "aoi3ylNhLdoSRdzWTYGinwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 19:44:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.54.52 (52.54.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:43:58.566670 2026] [security2:error] [pid 7128:tid 7128] [client 35.229.54.52:34510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ellesorority.com"] [uri "/.git/config"] [unique_id "aoiqfi0F2hPx7GD3GkWssAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack