๐ฎ๐ณ
evicky2002
2026-08-27 06:00:33
(11 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-08-27 05:14:42
(12 hours ago)
16 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs:
GET /.env.bak HTT ...
show more
16 attacks on env grabbing URLs, VC URLs, config grabbing URLs (type 2), PHP URLs:
GET /.env.bak HTTP/1.1
GET /.git/config HTTP/1.1
GET /config.json HTTP/1.1
GET /wp-config.php-backup HTTP/1.1
show less
Hacking
Web App Attack
๐ณ๐ฑ
enpepet
2026-08-26 19:55:38
(21 hours ago)
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 URL: ...
show more
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 URL:/.git/config
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-26 19:24:35
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:24:29.136311 2026] [security2:error] [pid 17565:tid 17565] [client 35.240.254.144:16112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "be4ventures.com"] [uri "/.git/config"] [unique_id "ao89bXhJUK5tyZFKph3iRQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 19:22:36
(22 hours ago)
PSCSERV WPSCAN 35.240.254.144
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:59:48
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:59:42.135507 2026] [security2:error] [pid 19616:tid 19616] [client 35.240.254.144:14004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bvisecurity.com"] [uri "/.git/config"] [unique_id "ao83noYygywht9nrb3vqLwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:42:22
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:42:17.836838 2026] [security2:error] [pid 4474:tid 4474] [client 35.240.254.144:17252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookguardian.net"] [uri "/.git/config"] [unique_id "ao8ziWUM6abhEwzfmGgFAQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-26 18:25:07
(23 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:24:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:24:42.735715 2026] [security2:error] [pid 3566:tid 3566] [client 35.240.254.144:29502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bofill.name"] [uri "/.git/config"] [unique_id "ao8varZVCogUzBILzNuxzwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 18:09:15
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:09:09.332956 2026] [security2:error] [pid 1834:tid 1834] [client 35.240.254.144:46854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigholegolf.com"] [uri "/.git/config"] [unique_id "ao8rxS3LfixeSO9CQHK_owAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-26 18:00:59
(23 hours ago)
Git config exposure probe
Web App Attack
Anonymous
2026-08-26 18:00:09
(23 hours ago)
apache vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 17:43:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.254.144 (144.254.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 13:43:23.975244 2026] [security2:error] [pid 31059:tid 31059] [client 35.240.254.144:12338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barbaraehill.com"] [uri "/.git/config"] [unique_id "ao8lu1zT_f5i5YWXxOULgQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-08-26 17:43:14
(23 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-26 17:42:26
(23 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot