🇩🇪
LRob
2026-08-26 19:24:55
(2 weeks ago)
Unauthorised SSH login attempts | 2026-08-26 19:24 UTC
Brute-Force
SSH
🇮🇹
VHosting
2026-08-05 03:15:03
(1 month ago)
Detected mail brute force attack from 4 different servers
Brute-Force
Anonymous
2026-06-28 01:36:35
(2 months ago)
40.65.61.40 - - [28/Jun/2026:10:36:28 +0900] "GET /.git/HEAD HTTP/1.1" 403 458 "-" "Mozilla/5.0 (Mac ...
show more
40.65.61.40 - - [28/Jun/2026:10:36:28 +0900] "GET /.git/HEAD HTTP/1.1" 403 458 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
40.65.61.40 - - [28/Jun/2026:10:36:32 +0900] "GET /.git/logs/HEAD HTTP/1.1" 403 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36 Edg/124.0.0.0"
40.65.61.40 - - [28/Jun/2026:10:36:34 +0900] "GET /.git/refs/heads/master HTTP/1.1" 403 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Brute-Force
🇬🇧
gws-hostmaster
2026-06-28 01:32:56
(2 months ago)
ModSecurity OWASP CRS (Anomaly Score: 13): Host header is a numeric IP address;Restricted File Acces ...
show more
ModSecurity OWASP CRS (Anomaly Score: 13): Host header is a numeric IP address;Restricted File Access Attempt;URL file extension is restricted by policy;
show less
Web App Attack
🇺🇸
nyt
2026-06-28 01:20:52
(2 months ago)
Sensitive File Probe, Attempt to access sensitive .git directory
Web App Attack
🇺🇸
RAP
2026-06-28 00:20:15
(2 months ago)
2026-06-28 00:20:15 UTC Unauthorized activity to TCP port 8443. Web App
Port Scan
Web App Attack
🇷🇸
Scan
2026-06-28 00:13:35
(2 months ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking
Anonymous
2026-06-28 00:01:30
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
🇮🇱
spd.co.il
2026-04-09 01:02:44
(5 months ago)
Web application attack detected
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-04-07 22:03:15
(5 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-06.
show less
Web App Attack
SSH
Hacking
🇨🇦
polycoda
2026-04-07 10:09:12
(5 months ago)
⌨️ Probes for /.git/config everywhere
Hacking
Web App Attack
🇩🇪
betternews.app
2026-04-07 00:12:24
(5 months ago)
"a web request contained keyword ".git"; Suspicious URL: /.git/config"
Web Spam
Blog Spam
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-07 00:06:15
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 20:06:09.269535 2026] [security2:error] [pid 517196:tid 517196] [client 40.65.61.40:61776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trucnghiem.com"] [uri "/.git/config"] [unique_id "adRKcRHzwxVPD0hDQsjDKgAAABU"], referer: https://www.reddit.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-06 23:38:55
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 19:38:47.275716 2026] [security2:error] [pid 684468:tid 684468] [client 40.65.61.40:63366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "san-marino-marine-consulting.com"] [uri "/.git/config"] [unique_id "adREB6IV6hhnJl_TKQbiBAAAAAI"], referer: https://www.google.com/search?q=
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-06 22:28:43
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 40.65.61.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 18:28:38.390225 2026] [security2:error] [pid 415100:tid 415100] [client 40.65.61.40:61601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rondeal.com"] [uri "/.git/config"] [unique_id "adQzloiuZzpgZFVNi-gZpgAAABY"], referer: https://www.yahoo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack