๐บ๐ธ
wordpresshosting.solutions
2026-09-29 12:16:35
(3 days ago)
Web app vulnerability scanning detected. Evidence: [IP] - - [29/Sep/2026:12:16:34 +0000] "GET /phpin ...
show more
Web app vulnerability scanning detected. Evidence: [IP] - - [29/Sep/2026:12:16:34 +0000] "GET /phpinfo.php HTTP/1.1" 404 45490 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
[IP] - - [29/Sep/2026:12:16:34 +0000] "GET /phpinfo.php HTTP/1.1" 404 45490 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-28 22:54:04
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 19:04:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 15:04:35.628991 2026] [security2:error] [pid 6557:tid 6557] [client 8.234.82.229:33996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.shhcenter.com"] [uri "/.git/config"] [unique_id "arlow8rp6bDZZs7Ok7Q7XwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 19:10:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 15:10:44.177366 2026] [security2:error] [pid 17508:tid 17508] [client 8.234.82.229:52200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calificacionyvalidacionsicav.com"] [uri "/.git/config"] [unique_id "argYtOMwJGy585tuWssc1AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:36:30
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:36:25.115862 2026] [security2:error] [pid 11679:tid 11679] [client 8.234.82.229:43192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lumentravel.com"] [uri "/.git/config"] [unique_id "arfmeT6nWervcqyYKvBP8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-09-26 08:25:08
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted] 8.234.82.229 (IN/India/229.82.234.8.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.234.82.229 (IN/India/229.82.234.8.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-25 19:24:46
(6 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2019.gr,www.aidshep2020.gr; logs=/var/log/httpd/ ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.aidshep2019.gr,www.aidshep2020.gr; logs=/var/log/httpd/domains/aidshep2019.gr.log,/var/log/httpd/domains/aidshep2020.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:48:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:47:55.186587 2026] [security2:error] [pid 29529:tid 29529] [client 8.234.82.229:34290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.elderlyassociation.org"] [uri "/.git/config"] [unique_id "arVwWyHd-CRMINRuB96CIgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-24 15:04:54
(1 week ago)
8.234.82.229 - - [24/Sep/2026:17:04:44 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 ...
show more
8.234.82.229 - - [24/Sep/2026:17:04:44 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.234.82.229 - - [24/Sep/2026:17:04:44 +0200] "GET /.env HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.234.82.229 - - [24/Sep/2026:17:04:44 +0200] "GET /.env.local HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.234.82.229 - - [24/Sep/2026:17:04:45 +0200] "GET /.env.production HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.234.82.229 - - [24/Sep/2026:17:04:45 +0200] "GET /.env.staging HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ซ๐ท
โจ
2026-09-24 00:27:05
(1 week ago)
Domain : accountant-pl.com
Rule : env
2026-09-24 00:26:03 ***hidden-privacy*** GET /.env.local - 443 ...
show more
Domain : accountant-pl.com
Rule : env
2026-09-24 00:26:03 ***hidden-privacy*** GET /.env.local - 443 - 8.234.82.229 HTTP/1.1 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - accountant-pl.com 404 0 0 1574 340 177 - -
show less
Hacking
SQL Injection
๐ฎ๐น
VHosting
2026-09-21 08:40:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-20 22:00:41
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-20
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 19:50:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.82.229 (229.82.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:50:34.531356 2026] [security2:error] [pid 5336:tid 5336] [client 8.234.82.229:38490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructionloansfunding.com"] [uri "/.git/config"] [unique_id "arA5Ch4Gz289Xnuo3CrCEwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-20 13:22:49
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: cluster.definitelynotahoneypot.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack