๐ง๐ช
cmbplf
2026-06-25 21:38:28
(2 days ago)
473 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-06-25 20:15:04
(2 days ago)
[Fri Jun 26 06:15:03.496544 2026] [security2:error] [pid 556723] [client 130.195.213.165:34786] [cli ...
show more
[Fri Jun 26 06:15:03.496544 2026] [security2:error] [pid 556723] [client 130.195.213.165:34786] [client 130.195.213.165] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/index"] [unique_id "aj2MR2vyS-HeTrbgsYtqqAAAAAA"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 19:48:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 15:48:43.206222 2026] [security2:error] [pid 13140:tid 13140] [client 130.195.213.165:38182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyclingboardgames.net"] [uri "/.git/index"] [unique_id "aj2GG7wcmzd12eKzLEtWhAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 18:12:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 14:12:08.580224 2026] [security2:error] [pid 2884:tid 2884] [client 130.195.213.165:43870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "athletefirst.org"] [uri "/.git/index"] [unique_id "aj1vePgcYHwbh5699RByhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-06-25 18:00:08
(2 days ago)
Auto-blocked: score 30 (threshold 10). Tier: HIGH. Hits: 4. Flags: git-exposure. Paths: /.git/index, ...
show more
Auto-blocked: score 30 (threshold 10). Tier: HIGH. Hits: 4. Flags: git-exposure. Paths: /.git/index, /.git/index, /.git/index, /.git/index
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 17:55:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 13:55:49.838103 2026] [security2:error] [pid 14029:tid 14029] [client 130.195.213.165:45934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assistfeed.com"] [uri "/.git/index"] [unique_id "aj1rpbo_pgoIvpIjum68twAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Smish
2026-06-25 17:31:43
(2 days ago)
HONEYPOT HIT --> Fail2ban time=1782408701 log=2026-06-25T18:31:41+01:00 ip=130.195.213.165 host=as21 ...
show more
HONEYPOT HIT --> Fail2ban time=1782408701 log=2026-06-25T18:31:41+01:00 ip=130.195.213.165 host=as210667.net method=GET uri="/.git/index" status=404 ua="moving-to-bins/1.0" ref="-" rid=80c95ed8beaa3359c265baa96fa62197
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 17:23:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 13:23:41.455627 2026] [security2:error] [pid 5811:tid 5811] [client 130.195.213.165:37942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "artocratic.com"] [uri "/.git/index"] [unique_id "aj1kHfsjIT2TT5LJ4hF_xAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 17:07:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 13:07:01.741384 2026] [security2:error] [pid 7381:tid 7401] [client 130.195.213.165:46166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowsinthequiver.com"] [uri "/.git/index"] [unique_id "aj1gNVjWYSKLSiyoMxYLiQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 16:41:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 12:41:29.783077 2026] [security2:error] [pid 26819:tid 26819] [client 130.195.213.165:50526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "architech.com"] [uri "/.git/index"] [unique_id "aj1aOWc_mmExR7xp6RdD3AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 16:35:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 11:06:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 130.195.213.165 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 07:06:45.940475 2026] [security2:error] [pid 417:tid 439] [client 130.195.213.165:33840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fiefblondel.com"] [uri "/.git/index"] [unique_id "ajPRRW2nnpiTj3lfpdlMjwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-18 10:48:22
(1 week ago)
[ThuJun1812:48:17.3000722026][security2:error][pid1716141:tid1716436][client130.195.213.165:0]ModSec ...
show more
[ThuJun1812:48:17.3000722026][security2:error][pid1716141:tid1716436][client130.195.213.165:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"felinescubicle.ch\"][uri\"/.git/index\"][unique_id\"ajPM8RUnIEzkDeiEbhSmYAAAAI0\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-18 10:46:34
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
rdpguard.com
2026-06-18 10:30:55
(1 week ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force