๐จ๐ญ
TheCoon
2026-05-31 17:00:02
(3 weeks ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ต๐ฑ
tkhaldi
2026-05-28 21:13:46
(3 weeks ago)
::ffff:8.230.107.30 - - [28/May/2026:21:13:45 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data?pa ...
show more
::ffff:8.230.107.30 - - [28/May/2026:21:13:45 +0000] "GET /wp-json/gravitysmtp/v1/tests/mock-data?page=gravitysmtp-settings HTTP/1.1" 400 650 "-" "Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.108 Safari/537.36 UCBrowser/12.13.0.1207"
::ffff:8.230.107.30 - - [28/May/2026:21:13:45 +0000] "GET /wp-json/gravitysmtp/v1/settings HTTP/1.1" 400 248 "-" "Konqueror/3.0-rc4; (Konqueror/3.0-rc4; i686 Linux;;datecode)"
::ffff:8.230.107.30 - - [28/May/2026:21:13:45 +0000] "GET /wp-json/gravitysmtp/v1/config HTTP/1.1" 400 248 "-" "Mozilla/5.0 (compatible; Konqueror/3.5; SunOS) KHTML/3.5.1 (like Gecko)"
...
show less
Web App Attack
๐บ๐ธ
zwebvigil
2026-05-28 21:10:31
(3 weeks ago)
8.230.107.30 [28/May/2026:14:10:31 -0700] "\x16\x03\x01" 400 226 "-" port=37816 "-" "-" "-" "-" 123 ...
show more
8.230.107.30 [28/May/2026:14:10:31 -0700] "\x16\x03\x01" 400 226 "-" port=37816 "-" "-" "-" "-" 123
8.230.107.30 [28/May/2026:14:10:31 -0700] "\x16\x03\x01" 400 226 "-" port=37818 "-" "-" "-" "-" 116
8.230.107.30 [28/May/2026:14:10:31 -0700] "\x16\x03\x01" 400 226 "-" port=37828 "-" "-" "-" "-" 156
8.230.107.30 [28/May/2026:14:10:31 -0700] "\x16\x03\x01" 400 226 "-" port=37840 "-"
show less
Web App Attack
๐น๐ท
Threat.live
2026-05-28 19:25:02
(3 weeks ago)
Suspicious Connection Attempts
Brute-Force
๐ฎ๐ช
AutosOnShow
2026-05-28 00:40:06
(4 weeks ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-05-28 00:39:46.708 |
Web App Attack
๐ฉ๐ช
4server
2026-05-27 07:27:48
(4 weeks ago)
[WedMay2709:27:43.4854552026][security2:error][pid2843463:tid2843491][client8.230.107.30:0]ModSecuri ...
show more
[WedMay2709:27:43.4854552026][security2:error][pid2843463:tid2843491][client8.230.107.30:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.tpgs.ch\"][uri\"/.git/config\"][unique_id\"ahac70uz6I2E5_SSR2EtigAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 07:18:10
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:18:02.854330 2026] [security2:error] [pid 8759:tid 8759] [client 8.230.107.30:40784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.angeltarrac.com"] [uri "/.git/config"] [unique_id "ahaaql2YxVPLReLe9vOEvgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 06:09:57
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 02:09:51.434985 2026] [security2:error] [pid 7334:tid 7334] [client 8.230.107.30:60520] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.technoware-lb.com"] [uri "/.git/config"] [unique_id "ahaKrx-m_goQV7xw0xyLlgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ParaBug
2026-05-27 06:00:24
(4 weeks ago)
8.230.107.30 - - [27/May/2026:08:00:24 +0200] "GET /.git/config HTTP/1.1" 301 3112 "-" "Mozilla/5.0 ...
show more
8.230.107.30 - - [27/May/2026:08:00:24 +0200] "GET /.git/config HTTP/1.1" 301 3112 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 Safari/537.36 OPR/62.0.3331.99"
...
show less
Phishing
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-05-27 05:14:02
(4 weeks ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-05-27 04:05:56
(4 weeks ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 03:59:44
(4 weeks ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:40:10
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:40:07.019786 2026] [security2:error] [pid 4905:tid 4905] [client 8.230.107.30:36332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hiddentcgcards.com"] [uri "/.git/config"] [unique_id "ahZnl0wg9uzN2iat7qgy8gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:08:07
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.107.30 (30.107.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:08:01.414989 2026] [security2:error] [pid 21589:tid 21589] [client 8.230.107.30:47350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.baughman.org"] [uri "/.git/config"] [unique_id "ahZgEYvcD3pNWvelboPgxgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-05-27 02:44:41
(4 weeks ago)
Login credentials theft attempt
Hacking