Anonymous
2026-09-25 13:15:02
(2 days ago)
fail2ban jail apache-secrets-probe: startupian.com:443 104.196.15.172 - - [23/Sep/2026:05:27:09 -070 ...
show more
fail2ban jail apache-secrets-probe: startupian.com:443 104.196.15.172 - - [23/Sep/2026:05:27:09 -0700] "GET /.git/config HTTP/1.1" 301 4538 "-" "-"
show less
Web App Attack
Anonymous
2026-09-24 13:45:10
(3 days ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.git/config
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:00:32
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-23
Web App Attack
SSH
Hacking
Anonymous
2026-09-23 21:07:04
(4 days ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-23 20:26:44.
Web App Attack
Anonymous
2026-09-23 20:51:37
(4 days ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.rebello.gr; logs=/var/log/httpd/domains/rebello.gr.log; ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.rebello.gr; logs=/var/log/httpd/domains/rebello.gr.log; samples=/.git/config
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:28:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:28:20.814459 2026] [security2:error] [pid 32441:tid 32441] [client 104.196.15.172:38824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realtorpaul.buynorthwest.com"] [uri "/.git/config"] [unique_id "arQ2ZHV7i_BDKp1ObNSLXwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 20:23:36
(4 days ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:11:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:11:08.587360 2026] [security2:error] [pid 22328:tid 22328] [client 104.196.15.172:58054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "realjasonchance.com"] [uri "/.git/config"] [unique_id "arQyXAK3PUHYOPkpMZpIcQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 20:10:03
(4 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:42:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:42:06.341989 2026] [security2:error] [pid 26066:tid 26066] [client 104.196.15.172:47676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "readyremotely.com"] [uri "/.git/config"] [unique_id "arQrjg5HZJeTfxsxurOCQgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sternwart
2026-09-23 19:39:30
(4 days ago)
Automatisch erkannt: Zugriff auf /.git/config (ready4future.ch)
Web App Attack
Bad Web Bot
๐บ๐ธ
lnklnx
2026-09-23 19:29:58
(4 days ago)
reader.lnklnx.com:443 104.196.15.172 - - [23/Sep/2026:14:29:55 -0500] "GET /.git/config HTTP/1.1" 30 ...
show more
reader.lnklnx.com:443 104.196.15.172 - - [23/Sep/2026:14:29:55 -0500] "GET /.git/config HTTP/1.1" 302 5512 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:21:38
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:21:33.502648 2026] [security2:error] [pid 14272:tid 14272] [client 104.196.15.172:39856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reachpoint.com"] [uri "/.git/config"] [unique_id "arQmvdBWy5JVLn2t2Qds-QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:39:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.15.172 (172.15.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:39:42.700132 2026] [security2:error] [pid 20561:tid 20561] [client 104.196.15.172:40644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdsparts.com"] [uri "/.git/config"] [unique_id "arQc7j4NpsbA1FKuPRA1VwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-09-23 14:29:09
(4 days ago)
\[Wed Sep 23 16:29:08.188985 2026\] \[:error\] \[pid 28734:tid 140352619017984\] \[client 104.196.15 ...
show more
\[Wed Sep 23 16:29:08.188985 2026\] \[:error\] \[pid 28734:tid 140352619017984\] \[client 104.196.15.172:52858\] \[client 104.196.15.172\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "static.162.187.46.78.clients.your-server.de"\] \[uri "/.git/config"\] \[unique_id "arPiNBO4KxZDgZH08fU78gAAAME"\]
show less
Brute-Force
Web App Attack