๐ฌ๐ง
AvonleaConsulting
2026-08-28 18:34:46
(24 minutes ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:21:52
(37 minutes ago)
(mod_security) mod_security (id:949110) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:21:48.040054 2026] [security2:error] [pid 16416:tid 16416] [client 8.228.108.49:52822] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.cescfoundation.org"] [uri "/.git/config"] [unique_id "apHRvOAuMmCQL2FYG_wYKAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:01:10
(57 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:01:04.236514 2026] [security2:error] [pid 18978:tid 18978] [client 8.228.108.49:56482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grdigitaldesigns.com"] [uri "/.git/config"] [unique_id "apHM4DFY_HV-VDm-DyG53QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 17:37:54
(1 hour ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:36:18
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:36:10.048807 2026] [security2:error] [pid 25158:tid 25158] [client 8.228.108.49:34868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcmu.org"] [uri "/.git/config"] [unique_id "apHHCrwC87RNsosxicYNPwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-08-28 17:19:37
(1 hour ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ต๐ฑ
Budyn
2026-08-28 17:18:15
(1 hour ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: i.budyn.ovh | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:12:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:12:11.260485 2026] [security2:error] [pid 9169:tid 9169] [client 8.228.108.49:50644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acmax.com"] [uri "/.git/config"] [unique_id "apHBaxOj0J1bt_MQd7zTkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-28 17:06:42
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 8.228.108.49 (US/United States/49.1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 8.228.108.49 (US/United States/49.108.228.8.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 17:03:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-08-28 18:59:19,154 fail2ban.filter [1478]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 18:59:19,154 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 212.227.154.251 - 2026-08-28 18:59:19cloudlinux2 fail2ban: 2026-08-28 18:59:27,273 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 8.231.230.97cloudlinux2 fail2ban: 2026-08-28 18:59:32,277 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 103.239.138.71 - 2026-08-28 18:59:32cloudlinux2 fail2ban: 2026-08-28 18:59:47,811 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 8.228.108.49 - 2026-08-28 18:59:47cloudlinux2 fail2ban: 2026-08-28 19:00:44,135 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 153.67.129.155 - 2026-08-28 19:00:44cloudlinux2 fail2ban: 2026-08-28 19:02:14,345 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 153.67.129.155 - 2026-08-28 19:02:14cloudlinux2 fail2ban: 2026-08-28 19:02:25,494 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Ban 153.67.129.155cloudlinux2 fail2ban: 2026-08-28 19:0
show less
Brute-Force
๐ฌ๐ง
myintarweb
2026-08-28 17:00:12
(1 hour ago)
8.228.108.49 - - [28/Aug/2026:18:00:10 +0100] 443 "GET /.git/config HTTP/1.1" 404 31016 "-" "-"
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:56:18
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.108.49 (49.108.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:56:14.295820 2026] [security2:error] [pid 16139:tid 16139] [client 8.228.108.49:47864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adrienberthaud.com"] [uri "/.git/config"] [unique_id "apG9rihseKx9lfm-Kg_y5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:42:05
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-08-28 16:39:49
(2 hours ago)
Cloudflare WAF: Request Path: /.git/config Request Query: Host: foro.elhacker.net userAgent: Actio ...
show more
Cloudflare WAF: Request Path: /.git/config Request Query: Host: foro.elhacker.net userAgent: Action: block Source: firewallManaged ASN Description: Google LLC Country: US Method: GET Timestamp: 2026-08-28T16:39:49Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-28 16:32:08
(2 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot