๐ฌ๐ง
andypiper
2026-08-23 01:01:40
(17 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-23 00:12:51
(18 hours ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 98.159.234.151 - - [18/Aug/2026:09:50:14 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 98.159.234.151 - - [18/Aug/2026:09:50:14 +0300] "GET /.git/config HTTP/1.1" 403 6296 "http://heraklion-bridge.gr/.git/config" "Go-http-client/2.0"
show less
Web App Attack
๐ฌ๐ท
mail.avx.gr
2026-08-21 17:37:07
(2 days ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 98.159.234.151 - - [18/Aug/2026:09:50:14 +0300] " ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 98.159.234.151 - - [18/Aug/2026:09:50:14 +0300] "GET /.git/config HTTP/1.1" 403 6296 "http://heraklion-bridge.gr/.git/config" "Go-http-client/2.0"
show less
Web App Attack
๐บ๐ธ
micropedro
2026-08-20 10:38:13
(3 days ago)
3 incidents: port scanning. First: 2026-06-01 05:50, Last: 2026-08-20 06:38 UTC. Triggers: non-publi ...
show more
3 incidents: port scanning. First: 2026-06-01 05:50, Last: 2026-08-20 06:38 UTC. Triggers: non-public-port,firewall-tcp,unknown.
show less
Port Scan
๐น๐ท
herseycokguzelolacak
2026-08-19 19:00:13
(3 days ago)
Persistent traffic from Blacklisted IP. Blocked via Kernel/NFLOG. (154 hits in 24h).
Port Scan
๐ณ๐ฑ
e.fierstra
2026-08-18 13:49:43
(5 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-18 13:45:12
(5 days ago)
Web App Attack
๐ฉ๐ช
paissangroup
2026-08-18 12:50:12
(5 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 12:36:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:36:49.601220 2026] [security2:error] [pid 3750:tid 3750] [client 98.159.234.151:25191] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "horseillustration.com"] [uri "/.git/config"] [unique_id "aoRR4U0eroCcbUn_2dHyYgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 12:21:32
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:21:24.308600 2026] [security2:error] [pid 4992:tid 5273] [client 98.159.234.151:55941] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "busybeerestaurant.com"] [uri "/.git/config"] [unique_id "aoRORFYI0w1KDh7dVex-kwAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-18 10:18:50
(5 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ง๐ช
voormedia
2026-08-18 09:48:14
(5 days ago)
Accessed trap at '/.git/config'
Web App Attack
๐ฉ๐ช
LRob
2026-08-18 09:48:14
(5 days ago)
Credential and secrets file probing | req: /.git/config | UA: Go-http-client/1.1
Hacking
Web App Attack
๐ช๐ธ
el-brujo
2026-08-18 09:47:52
(5 days ago)
18/Aug/2026:11:47:52.710884 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Aug/2026:11:47:52.710884 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 98.159.234.151] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.git/config"] [unique_id "aoQqSHcgScsz232B6yfcWAAF32g"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 08:51:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in th ...
show more
(mod_security) mod_security (id:210492) triggered by 98.159.234.151 (suo.dreamsinheels.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 04:51:24.947861 2026] [security2:error] [pid 25807:tid 25807] [client 98.159.234.151:40893] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indoorsfinishing.com"] [uri "/.git/config"] [unique_id "aoQdDOqB3_egg1Wd3G8yCQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack