Anonymous
2026-10-02 10:31:34
(1 day ago)
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web s ...
show more
Fail2Ban: request for a known-malicious path (.env, .git, wp-login, actuator, ...) on a public web server; honeypot hit, banned on first attempt.
show less
Web App Attack
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2026-10-02 02:55:51
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 02:48:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:48:51.717807 2026] [security2:error] [pid 14604:tid 14624] [client 35.247.188.7:54360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inal.org"] [uri "/.git/config"] [unique_id "ar8bk_niQDMTmD2h9mKt1AAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 01:52:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:52:48.053600 2026] [security2:error] [pid 20213:tid 20213] [client 35.247.188.7:44652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "impgs.com"] [uri "/.git/config"] [unique_id "ar8OcD6iKPTLawYM6ZCFuAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
zenmorro
2026-10-02 01:51:38
(1 day ago)
Honeypot hit (imperocms:0) โ [honeypot] Tentativo lettura .git/config | GET /.git/config. Automated ...
show more
Honeypot hit (imperocms:0) โ [honeypot] Tentativo lettura .git/config | GET /.git/config. Automated report from honeypot infrastructure
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-02 01:36:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:36:52.903735 2026] [security2:error] [pid 14707:tid 14733] [client 35.247.188.7:44906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "impact.gryphix.com"] [uri "/.git/config"] [unique_id "ar8KtMzI9v8CtzrwgC43sAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 01:29:50
(1 day ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.247.188.7 - - \[02/Oct/2026:03:29:40 +0200\] "GET /.git/config HTTP/1.1" 404 7424 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-10-02 01:04:50
(1 day ago)
[REDACTED] 35.247.188.7 - - [02/Oct/2026:03:04:50 +0200] "GET /.git/config HTTP/1.1" 200 7473 "-" "- ...
show more
[REDACTED] 35.247.188.7 - - [02/Oct/2026:03:04:50 +0200] "GET /.git/config HTTP/1.1" 200 7473 "-" "-"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Thermogenic
2026-10-02 01:02:52
(1 day ago)
Fail2Ban nginx-scanners: automated vulnerability scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 00:51:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.188.7 (7.188.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:51:09.944581 2026] [security2:error] [pid 12885:tid 12885] [client 35.247.188.7:46900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imjustsayin.yeswedeliver.org"] [uri "/.git/config"] [unique_id "ar7__ZfPeAlyOc1GDCZEtwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
maxasp.net
2026-10-02 00:29:30
(1 day ago)
Inc-HTTP-Safe Reject, collection = Risk Profile; Attack Var: IP Address; Attack Data: High Abuse Sco ...
show more
Inc-HTTP-Safe Reject, collection = Risk Profile; Attack Var: IP Address; Attack Data: High Abuse Score (reason code 13); Abuse Score: 100; Usage Type: Data Center/Web Hosting/Transit; ip attacks: 1; subnet attacks: 1
show less
SQL Injection
๐ซ๐ท
โจ
2026-10-02 00:04:04
(1 day ago)
Domain : imgdocs.gestioncgt.es
Rule : config
2026-10-02 00:02:33 ***hidden-privacy*** GET /.git/conf ...
show more
Domain : imgdocs.gestioncgt.es
Rule : config
2026-10-02 00:02:33 ***hidden-privacy*** GET /.git/config - 443 - 35.247.188.7 HTTP/1.1 - - imgdocs.gestioncgt.es 404 8 0 300 100 657 - -
show less
Hacking
SQL Injection
๐ฉ๐ช
Hary74656
2026-10-01 23:54:48
(1 day ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 35.247.188.7] [realclient ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 35.247.188.7] [realclient 35.247.188.7] [02/Oct/2026:01:54:47 +0200] [vhost schani.hostmi.at] 403 "GET /.git/config HTTP/1.1"
show less
Web App Attack
๐ฉ๐ช
LRob
2026-10-01 23:43:05
(1 day ago)
Secret file probe | method: GET | path: /.git/config | ua: -
Hacking
Web App Attack
Anonymous
2026-10-01 23:42:45
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; samples=/.git/config
show less
Hacking
Web App Attack