๐ซ๐ฎ
kumiko
2026-09-29 13:59:54
(38 minutes ago)
[2026-09-29 16:59:54] Probing for dotfiles
"GET /.git/config HTTP/1.1" 301
Bad Web Bot
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-26 23:49:35
(2 days ago)
Persistent attacker, repeat offender
Hacking
๐ฆ๐บ
Klaverstyn
2026-09-26 08:07:43
(3 days ago)
Repeated 403 Forbidden responses
Web App Attack
๐จ๐ฆ
Anytech
2026-09-25 21:19:29
(3 days ago)
Blocked by ConnMonitor
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 21:12:22
(3 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 8.234.202.210 - - [25/Sep/2026:23:12:05 +0200] "GET /.git/config HTTP/1.1" 404 73176 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:26:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:26:24.724919 2026] [security2:error] [pid 7316:tid 7333] [client 8.234.202.210:59482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.certifiedfinancialanalyst.org"] [uri "/.git/config"] [unique_id "arV5YFZEwBGzjUVxHmSKGwAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:40:22
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:40:17.951524 2026] [security2:error] [pid 29318:tid 29318] [client 8.234.202.210:38300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.centralbaptistalcoa.org"] [uri "/.git/config"] [unique_id "arVukaoxytq8ABOa9wODLgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-24 18:14:39
(4 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
rh24
2026-09-24 16:58:10
(4 days ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 8.234.202.210 (US/United States/210.202.2 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 8.234.202.210 (US/United States/210.202.234.8.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 16:50:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 12:49:53.093002 2026] [security2:error] [pid 25618:tid 25618] [client 8.234.202.210:58986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.seacorre.de"] [uri "/.git/config"] [unique_id "arVUseM_44i_GnnWP6IQigAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-24 16:20:49
(4 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-09-24 15:20:32
(4 days ago)
Web exploit or injection attempt blocked by ModSecurity WAF.
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:06:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:06:02.986129 2026] [security2:error] [pid 2641:tid 2641] [client 8.234.202.210:51506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "s.getitenglish.com"] [uri "/.git/config"] [unique_id "arShqscPKLGrnNCQTu7pBQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:00:44
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 20:33:48
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.202.210 (210.202.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:33:42.938373 2026] [security2:error] [pid 20620:tid 20620] [client 8.234.202.210:40116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "techskill.net"] [uri "/.git/config"] [unique_id "arBDJqmwycLckcWKJHAFjgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack