๐ง๐ช
sid3windr
2026-06-12 06:10:10
(1 day ago)
GET /.git/HEAD (Tarpitted for 1d15h8m28s, wasted 8.06MB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 19:36:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 48.214.55.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 48.214.55.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 15:36:39.724069 2026] [security2:error] [pid 12986:tid 12986] [client 48.214.55.58:1947] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.21"] [uri "/.git/HEAD"] [unique_id "aim8x-Afk5iSUqBjgAneuAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 18:15:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 48.214.55.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 48.214.55.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 14:14:58.064374 2026] [security2:error] [pid 28935:tid 28935] [client 48.214.55.58:3103] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.177"] [uri "/.git/HEAD"] [unique_id "aimpoizE_w24dXEGnWCQgwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kexol
2026-06-10 18:09:34
(2 days ago)
multiport scan, 2 ports scanned: 8080, 8443
Port Scan
๐จ๐ฆ
Slackin' Jack
2026-06-10 17:15:45
(2 days ago)
Triggered honeypot on port 2083. (48.214.55.58)
Port Scan
๐บ๐ธ
Moby
2026-06-10 17:01:46
(2 days ago)
48.214.55.58 - - [10/Jun/2026:12:01:41 -0500] "GET /.git/HEAD HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Ma ...
show more
48.214.55.58 - - [10/Jun/2026:12:01:41 -0500] "GET /.git/HEAD HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14.4; rv:125.0) Gecko/20100101 Firefox/125.0" "98.194.227.56" "98.194.227.56"
48.214.55.58 - - [10/Jun/2026:12:01:42 -0500] "GET /.git/config HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Linux; Android 14; Pixel 8) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Mobile Safari/537.36" "98.194.227.56" "98.194.227.56"
48.214.55.58 - - [10/Jun/2026:12:01:44 -0500] "GET /.env.local HTTP/1.1" 404 985 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4 Safari/605.1.15" "98.194.227.56" "98.194.227.56"
...
show less
Web App Attack
๐บ๐ธ
jkhorvath.com
2026-06-10 16:49:15
(2 days ago)
Request for URL /.git/HEAD
Phishing
Brute-Force
Web App Attack
๐บ๐ธ
RAP
2026-06-10 16:37:39
(2 days ago)
2026-06-10 16:37:39 UTC Unauthorized activity to TCP port 8443. Web App
Port Scan
Web App Attack
๐ฉ๐ช
maxpower
2026-06-10 15:31:53
(2 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 48.214.55.58 (US/United States/-): 2 in ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 48.214.55.58 (US/United States/-): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 48.214.55.58 - - [10/Jun/2026:17:31:36 +0200] "GET /wp-config.php.bak HTTP/1.1" 403 10402 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=145.239.233.178
48.214.55.58 - - [10/Jun/2026:17:31:37 +0200] "GET /.aws/credentials HTTP/1.1" 404 10401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "-" host=145.239.233.178
show less
Port Scan
๐ต๐ฑ
UMP-PL
2026-06-10 15:17:21
(2 days ago)
Webserver scan (backups, phpadmin, etc.)
Web App Attack
๐บ๐ธ
MakoWish
2026-06-10 15:09:33
(2 days ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐บ๐ธ
lnklnx
2026-06-10 14:50:35
(2 days ago)
www.lnklnx.com:80 48.214.55.58 - - [10/Jun/2026:09:50:33 -0500] "GET /.git/config HTTP/1.1" 301 595 ...
show more
www.lnklnx.com:80 48.214.55.58 - - [10/Jun/2026:09:50:33 -0500] "GET /.git/config HTTP/1.1" 301 595 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
Cyber Crusader
2026-06-10 07:34:35
(3 days ago)
Hundreds of Attempts (at least) to Connect to and Access Firewall Ports
Port Scan
Hacking
Brute-Force