🇹🇼
tye
2026-08-22 07:44:08
(1 week ago)
Wazuh Alert Evidence: 104.199.147.5 (104.199.147.5) - - [22/Aug/2026:15:44:06 +0800] "GET /.git/conf ...
show more
Wazuh Alert Evidence: 104.199.147.5 (104.199.147.5) - - [22/Aug/2026:15:44:06 +0800] "GET /.git/config HTTP/1.1" 404 5192 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
🇺🇸
FreeMyIP
2026-08-22 07:23:31
(1 week ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-08-22 07:22:06
(1 week ago)
104.199.147.5 - - [22/Aug/2026:09:22:06 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
104.199.147.5 - - [22/Aug/2026:09:22:06 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
🇹🇼
ip4.tw
2026-08-22 07:19:01
(1 week ago)
Malicious web scan
Hacking
Web App Attack
🇦🇺
Block Rockin' Beats
2026-08-22 07:16:04
(1 week ago)
Scanning for exploitable scripts
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 07:15:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:15:17.161988 2026] [security2:error] [pid 5039:tid 5039] [client 104.199.147.5:22012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meridianranchdrc.org"] [uri "/.git/config"] [unique_id "aolMhehAvcPhKE6_MSQAEQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-08-22 07:07:21
(1 week ago)
Try to access /.git/config
Web App Attack
🇳🇱
MM-bot
2026-08-22 07:05:47
(1 week ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-08-22 09:05:47 UTC+2)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-22 06:57:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:57:45.384140 2026] [security2:error] [pid 19148:tid 19158] [client 104.199.147.5:37156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tierrasolymar.com"] [uri "/.git/config"] [unique_id "aolIaSHO5xA1z4X7pMKOmAAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 06:41:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.147.5 (5.147.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:41:25.173078 2026] [security2:error] [pid 27654:tid 27654] [client 104.199.147.5:59522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "805.productions"] [uri "/.git/config"] [unique_id "aolElRBcnqGwBIs_uLAwcAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-22 06:41:26
(1 week ago)
Web attack/malicious scanning detected
Web App Attack