๐ฌ๐ง
openstrike.co.uk
2026-10-04 05:14:22
(2 days ago)
3 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ฟ๐ฆ
conure.sh
2026-10-03 12:00:51
(2 days ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 2 domain(s) in 2s
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-10-03 05:13:46
(3 days ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-03 04:30:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:30:40.776626 2026] [security2:error] [pid 18110:tid 18110] [client 136.113.199.240:36944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.graphicsbyrc.zavijava.net"] [uri "/.git/config"] [unique_id "asCE8BYcetmqoSEvPrNXBgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 04:21:40
(3 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-10-03 04:00:39
(3 days ago)
CMS/framework probe: 136.113.199.240 - - [03/Oct/2026:06:00:39 +0200] "GET /.git/config HTTP/1.1" 30 ...
show more
CMS/framework probe: 136.113.199.240 - - [03/Oct/2026:06:00:39 +0200] "GET /.git/config HTTP/1.1" 301 178 "-" "-" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:52:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:52:40.426158 2026] [security2:error] [pid 11893:tid 11893] [client 136.113.199.240:33736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gotdt.com.tlambert.us"] [uri "/.git/config"] [unique_id "asB8CFt9LRoSNyJ5H5ZZUgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-03 03:46:54
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
kkw
2026-10-03 03:45:40
(3 days ago)
[REDACTED] 136.113.199.240 - - [03/Oct/2026:05:45:40 +0200] "GET /.git/config HTTP/1.1" 302 4560 "-" ...
show more
[REDACTED] 136.113.199.240 - - [03/Oct/2026:05:45:40 +0200] "GET /.git/config HTTP/1.1" 302 4560 "-" "-"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-03 03:39:28
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-10-03 03:26:03
(3 days ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:24:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:24:08.445141 2026] [security2:error] [pid 4331:tid 4331] [client 136.113.199.240:43746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.golfclearance.com.au.bigholegolf.com"] [uri "/.git/config"] [unique_id "asB1WKImV_Z_BWGL0JWbqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
0x44
2026-10-03 03:10:41
(3 days ago)
Web probing - backdoors/webshells with missing User-Agent
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-03 02:57:42
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: www.goblinpot.store | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 02:36:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 136.113.199.240 (240.199.113.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 22:35:56.411398 2026] [security2:error] [pid 22809:tid 22809] [client 136.113.199.240:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.globetechsecurities.com"] [uri "/.git/config"] [unique_id "asBqDN71Du9ENT8m5dzWWwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack