Anonymous
2026-09-24 10:20:18
(1 hour ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-24 04:31:43
(7 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ซ๐ท
service Informatique
2026-09-24 04:00:37
(7 hours ago)
/.git
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 21:59:39
(13 hours ago)
Auto-ban: >3000 req/min op 2026-09-23
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 21:06:12
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:06:06.094935 2026] [security2:error] [pid 2913:tid 3032] [client 35.237.255.219:50206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "retnetsos.com"] [uri "/.git/config"] [unique_id "arQ_PtNpKGAm4dbHTAAwaQAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:50:13
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:50:08.038366 2026] [security2:error] [pid 25963:tid 25963] [client 35.237.255.219:41964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resume.alexsource.com"] [uri "/.git/config"] [unique_id "arQ7gM83VMp7BKhdmZbhrwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:32:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:32:36.770898 2026] [security2:error] [pid 24655:tid 24655] [client 35.237.255.219:55484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "restaurant-napkins.com"] [uri "/.git/config"] [unique_id "arQ3ZNJeldDwH7jq7Ts1VgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-23 20:12:27
(15 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:08:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:08:51.511707 2026] [security2:error] [pid 4653:tid 4669] [client 35.237.255.219:37730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "resort4pets.petsentiments.com"] [uri "/.git/config"] [unique_id "arQx0zUbQETLfbvG5W31UwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-23 20:06:54
(15 hours ago)
35.237.255.219 - - [23/Sep/2026:23:06:54 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "-"
...
Hacking
Web App Attack
Anonymous
2026-09-23 19:55:02
(15 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:51:52
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:51:46.048376 2026] [security2:error] [pid 29508:tid 29508] [client 35.237.255.219:42900] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "resilientpathconsulting.net"] [uri "/.git/config"] [unique_id "arQt0nSToaD4tANbvo8pIQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 19:38:32
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:19:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.255.219 (219.255.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:19:14.373599 2026] [security2:error] [pid 1259:tid 1259] [client 35.237.255.219:34916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "researchdesk.jmnr.net"] [uri "/.git/config"] [unique_id "arQmMp6CM_nyHvoiKzLQCAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack