๐ณ๐ฑ
erwindecker
2026-09-17 20:59:22
(1 day ago)
...
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 08:10:15
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-17 02:28:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.116.168 (168.116.230.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.116.168 (168.116.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:28:14.076187 2026] [security2:error] [pid 21121:tid 21121] [client 8.230.116.168:45068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yellowbrickfoundation.com"] [uri "/.git/config"] [unique_id "aqtQPu_Zh8TyZS-FRsnsaAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-09-17 02:27:08
(2 days ago)
Domain : yellingyin.com
Rule : hack
2026-09-17 02:25:11 ***hidden-privacy*** GET /.env.bak - 443 - 8 ...
show more
Domain : yellingyin.com
Rule : hack
2026-09-17 02:25:11 ***hidden-privacy*** GET /.env.bak - 443 - 8.230.116.168 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - yellingyin.com 404 0 2 1560 289 121 - -
show less
Hacking
SQL Injection
Brute-Force
๐ฉ๐ช
igerman
2026-09-16 14:52:42
(2 days ago)
caddy probes: env-probe: GET /.env(DROP), GET /.env.bak(DROP), GET /.env.development(DROP), GET /.en ...
show more
caddy probes: env-probe: GET /.env(DROP), GET /.env.bak(DROP), GET /.env.development(DROP), GET /.env.local(DROP), GET /.env.production(DROP), GET /.env.remote(DROP), GET /.env.staging(DROP), GET /.env.test(DROP) | git-repo: GET /.git/config(DROP) | web: GET /(404), GET /credentials.json(404), GET /gcp-credentials.json(404), GET /gcp-key.json(DROP), GET /gcp-sa.json(DROP), GET /google-credentials.json(404), GET /i.php(DROP), GET /info.php(DROP), GET /php.php(DROP), GET /phpinfo(DROP), GET /phpinfo.php(DROP), GET /pi.php(DROP), GET /pinfo.php(DROP), GET /sa.json(DROP), GET /service-account.json(DROP), GET /test.php(DROP)
show less
Web App Attack
๐ซ๐ท
suble.org
2026-09-16 02:59:16
(3 days ago)
[Wed Sep 16 04:59:15.847246 2026] [access_compat:error] [pid 850263:tid 850263] [client 8.230.116.16 ...
show more
[Wed Sep 16 04:59:15.847246 2026] [access_compat:error] [pid 850263:tid 850263] [client 8.230.116.168:41958] AH01797: client denied by server configuration: /var/www/vhosts/suble.org/xbkupx/
[Wed Sep 16 04:59:15.973881 2026] [access_compat:error] [pid 850263:tid 850263] [client 8.230.116.168:41958] AH01797: client denied by server configuration: /var/www/vhosts/suble.org/xbkupx/
[Wed Sep 16 04:59:16.097342 2026] [access_compat:error] [pid 850263:tid 850263] [client 8.230.116.168:41958] AH01797: client denied by server configuration: /var/www/vhosts/suble.org/xbkupx/
[Wed Sep 16 04:59:16.219276 2026] [access_compat:error] [pid 850263:tid 850263] [client 8.230.116.168:41958] AH01797: client denied by server configuration: /var/www/vhosts/suble.org/xbkupx/
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 01:32:11
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 00:07:41
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:01:04
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 22:14:13
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 8.230.116.168 (168.116.230.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.230.116.168 (168.116.230.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:14:04.570682 2026] [security2:error] [pid 9582:tid 9582] [client 8.230.116.168:60766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xarq.es"] [uri "/.git/config"] [unique_id "aqnDLIF9aUKoe-Vuu0ToWQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-15 21:11:12
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 20:55:18
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-15 18:49:29
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ง๐พ
lns.bz
2026-09-15 15:30:03
(3 days ago)
Too many 404 requests [BY]
Web App Attack