๐ณ๐ฑ
middelkoopcc
2026-09-27 04:54:01
(15 hours ago)
2026-09-27 06:50:52 GET /.git/config [404] && 2026-09-27 06:50:54 GET /.env [404] && 2026-09-27 06:5 ...
show more
2026-09-27 06:50:52 GET /.git/config [404] && 2026-09-27 06:50:54 GET /.env [404] && 2026-09-27 06:50:58 GET /.env.bak [404] && 189 more within 20 minutes
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-27 04:50:10
(15 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-27 04:38:23
(15 hours ago)
35.253.180.11 - - [27/Sep/2026:06:38:19 +0200] "GET /.env.remote HTTP/1.1" 404 508 "-" "Mozilla/5.0 ...
show more
35.253.180.11 - - [27/Sep/2026:06:38:19 +0200] "GET /.env.remote HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.253.180.11 - - [27/Sep/2026:06:38:19 +0200] "GET /.env.bak HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.253.180.11 - - [27/Sep/2026:06:38:20 +0200] "GET /.env.backup HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.253.180.11 - - [27/Sep/2026:06:38:20 +0200] "GET /.env.save HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.253.180.11 - - [27/Sep/2026:06:38:20 +0200] "GET /.env.old HTTP/1.1" 404 508 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.253.180.11 - - [27/Sep/2026:06:38:20 +0200] "GET /
show less
Web App Attack
Hacking
๐ง๐ช
Saec
2026-09-25 19:18:46
(2 days ago)
Jarvis auto-ban: Honeypot /.git/config via tersinte.saec.me [US] ASN:Google LLC
Port Scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-25 04:25:41
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ต๐ฑ
Budyn
2026-09-25 02:31:46
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.goblinpot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:52:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:51:57.744053 2026] [security2:error] [pid 13806:tid 13806] [client 35.253.180.11:49552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.omahareact.org"] [uri "/.git/config"] [unique_id "arWNbdIdCMoVEN4ZjmIFSQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:27:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:27:28.907321 2026] [security2:error] [pid 32140:tid 32140] [client 35.253.180.11:44426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.oldkentuckyhams.org"] [uri "/.git/config"] [unique_id "arV5oHs4rZc-zFxHF6N7igAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:43:07
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:43:03.594282 2026] [security2:error] [pid 17588:tid 17607] [client 35.253.180.11:40606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.okorganicgardening.org"] [uri "/.git/config"] [unique_id "arVvN7If0L-qbTuWTlgV0wAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:23:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.180.11 (11.180.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:23:08.823730 2026] [security2:error] [pid 17842:tid 17842] [client 35.253.180.11:49924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.okeetokee.org"] [uri "/.git/config"] [unique_id "arVqjLtjrWHTY_1AB9LBxQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 22:12:10
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-22 10:38:03
(5 days ago)
20 attempts against mh_ha-misbehave-ban on mist
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 08:20:21
(5 days ago)
20 attempts against mh-misbehave-ban on chard
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 08:00:04
(5 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-21 22:33:40
(5 days ago)
Web application attack detected.
Web App Attack