๐น๐ท
neron
2026-07-30 03:06:18
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-29 02:19:38
(4 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-07-28 12:54:38
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ญ๐ณ
unph
2026-07-15 06:52:54
(1 month ago)
Intento de acceso sospechoso bloqueado por AbuseIPDB Blocker Plugin
Brute-Force
๐ฏ๐ต
beon
2026-07-15 01:22:37
(1 month ago)
[DateTime=>2026-07-15T01:22:37Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/HEAD] , [total_Hit= ...
show more
[DateTime=>2026-07-15T01:22:37Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/HEAD] , [total_Hit=>once]
show less
Bad Web Bot
Web App Attack
Hacking
๐ฟ๐ฆ
conure.sh
2026-07-14 22:43:41
(1 month ago)
csagent: score 18.8: secrets grab x2; 2 domain(s) in 22s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 08:16:07
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 04:16:02.050351 2026] [security2:error] [pid 21077:tid 21077] [client 45.130.203.159:23345] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "olivia.krakowski.org"] [uri "/.git/HEAD"] [unique_id "alSewoemlIDAJ7PPsB4PeAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 02:31:08
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 22:31:01.603964 2026] [security2:error] [pid 12871:tid 12871] [client 45.130.203.159:59827] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.etudesoftware.com"] [uri "/.git/HEAD"] [unique_id "alRN5U8RaE3S-VjQO_cJ-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
Renรฉ Hickersberger
2026-07-13 00:50:44
(1 month ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Python-urllib/3.10"
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 00:13:17
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 20:13:13.386082 2026] [security2:error] [pid 19993:tid 19993] [client 45.130.203.159:61659] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chicagoholidaycards.com"] [uri "/.git/HEAD"] [unique_id "alQtmbBw75IikS_-Zp5vXAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 21:46:37
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.130.203.159 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 17:46:31.946674 2026] [security2:error] [pid 5583:tid 5583] [client 45.130.203.159:61641] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.knowledgepreservationalliance.com"] [uri "/.git/HEAD"] [unique_id "alQLNyu9GtIq_wm4Ev9xJQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tsZero
2026-07-09 10:50:55
(1 month ago)
Scan example: path=/.git/HEAD status=403
Hacking
๐ซ๐ท
masterguru
2026-07-09 01:17:29
(1 month ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.130.203.159 (EG/Egypt/-): 1 in the ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 45.130.203.159 (EG/Egypt/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ญ๐บ
kranem
2026-07-08 21:00:39
(1 month ago)
Triggered Cloudflare WAF from DE.
Action taken: BLOCK
ASN: 137409 (GSL Networks Pty LTD)
Protocol: H ...
show more
Triggered Cloudflare WAF from DE.
Action taken: BLOCK
ASN: 137409 (GSL Networks Pty LTD)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/HEAD
Timestamp: 2026-07-08T18:44:55Z
User-Agent: Python-urllib/3.10
show less
Bad Web Bot
๐ฌ๐ง
OptimusGO
2026-07-04 00:39:12
(1 month ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-07-04 01:39:12 UTC
Log evidence:
45.130.203.159 - - [04/Jul/2026:01:39:11 +0100] "GET /.git/HEAD HTTP/1.1" 301 162 "-" "Python-urllib/3.10"
07/04/2026-01:39:11.156384 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 45.130.203.159:46345 -> 185.127.18.66:80
07/04/2026-01:39:11.156384 [**] [1:1000112:1] SECURITY CRITICAL: Git Config File Access Attempt [**] [Classification: Attempted Administrator Privilege Gain] [Priority: 1] {TCP} 45.130.203.159:46345 -> 185.127.18.66:80
show less
Port Scan
Brute-Force