๐บ๐ธ
TPI-Abuse
2026-08-28 10:13:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:13:27.118545 2026] [security2:error] [pid 4583:tid 4583] [client 104.23.160.31:10658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.michaelhick.com"] [uri "/.git/HEAD"] [unique_id "apFfR67HdxRnRwmXrVkqvgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-08-28 04:21:56
(2 days ago)
104.23.160.31 - - [28/Aug/2026:06:21:53 +0200] "GET /.git/HEAD HTTP/2.0" 403 230 "-" "Mozilla/5.0 (W ...
show more
104.23.160.31 - - [28/Aug/2026:06:21:53 +0200] "GET /.git/HEAD HTTP/2.0" 403 230 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:06:11
(2 days ago)
Trying to access config files
Web App Attack
๐บ๐ธ
technojoe99
2026-08-28 03:59:35
(2 days ago)
Exploit scan from 104.23.160.31. GET /.git/config HTTP/2.0.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 00:53:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:53:50.495138 2026] [security2:error] [pid 22510:tid 22510] [client 104.23.160.31:11241] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.hker.org"] [uri "/.git/HEAD"] [unique_id "apDcHrtuzz18M2eMPme6jAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:43:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:42:55.071111 2026] [security2:error] [pid 10375:tid 10375] [client 104.23.160.31:10239] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.wcspeedway.com"] [uri "/.git/config"] [unique_id "apDLfwuKV6Ek-Amzl4PYoAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-27 22:31:37
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:26:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:26:19.348919 2026] [security2:error] [pid 423:tid 423] [client 104.23.160.31:10134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arnoldwell.com"] [uri "/.git/config"] [unique_id "apA6-3flVAqX0LHJp-OVFQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:46:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:46:28.098263 2026] [security2:error] [pid 15347:tid 15347] [client 104.23.160.31:13963] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.shafoo.com"] [uri "/.git/config"] [unique_id "apAjlJgoFIJdvZlMEABLhAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 10:59:05
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-08-27 07:06:57
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:28:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:28:06.929443 2026] [security2:error] [pid 20261:tid 20261] [client 104.23.160.31:11260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.beckerbrokerage.net"] [uri "/.git/config"] [unique_id "ao-81kh7avpcMlY92F4PXQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 00:30:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:30:13.534447 2026] [security2:error] [pid 18001:tid 18001] [client 104.23.160.31:12439] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.alexthepunk.com"] [uri "/.git/config"] [unique_id "ao-FFYRBOp2Hzbt6TASvkgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
securejdprop
2026-08-26 22:56:02
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/vpatch-git-config.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 20:38:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 104.23.160.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 16:38:04.537182 2026] [security2:error] [pid 28924:tid 28924] [client 104.23.160.31:11184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eurosoni.com"] [uri "/.git/HEAD"] [unique_id "ao9OrAMC0pLP3yTAKAZuHwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack