🇺🇸
LSPCCU
2026-09-08 05:08:04
(2 hours ago)
TSEC Honeypot Network report. Threat score: 65/100. Categories: Hacking, Brute-Force, Web App Attack ...
show more
TSEC Honeypot Network report. Threat score: 65/100. Categories: Hacking, Brute-Force, Web App Attack, SSH. Honeypot: h0neytr4p. Context: 136.118.41.40 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-09-08 05:07:05
(2 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-08 04:49:58.
Web App Attack
🇫🇷
ELYAZ
2026-09-08 04:56:48
(2 hours ago)
(y3) Failed access -byebye- from 136.118.41.40 (US/United States/40.41.118.136.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 136.118.41.40 (US/United States/40.41.118.136.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-08 04:56:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:56:06.871543 2026] [security2:error] [pid 32634:tid 32634] [client 136.118.41.40:49424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yosalvationyo.org"] [uri "/.git/config"] [unique_id "ap-VZnIDu56mXOLI_I5GoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-08 04:40:37
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
🇩🇪
McClay
2026-09-08 04:37:48
(2 hours ago)
Illegal access attempt:136.118.41.40 - - [08/Sep/2026:06:37:47 +0200] "GET /.git/config HTTP/1.1" 40 ...
show more
Illegal access attempt:136.118.41.40 - - [08/Sep/2026:06:37:47 +0200] "GET /.git/config HTTP/1.1" 401 5233 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-08 04:35:23
(2 hours ago)
2.889 requests with url.path */.git/config
836 requests with url.path *.git/*
Brute-Force
Bad Web Bot
Anonymous
2026-09-08 04:35:03
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇳🇿
Antinson
2026-09-08 04:35:01
(2 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇬🇧
consul.to
2026-09-08 04:34:41
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:33:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:33:52.254288 2026] [security2:error] [pid 3672:tid 3672] [client 136.118.41.40:55642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vanduijnencoaching.nl"] [uri "/.git/config"] [unique_id "ap-QMITJ3DBVBOvW0lV3tQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 04:29:43
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
OceanTreasure
2026-09-08 04:25:16
(2 hours ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-09-08T04:21:34Z [proxy]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:15:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.118.41.40 (40.41.118.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:15:42.467250 2026] [security2:error] [pid 5092:tid 5092] [client 136.118.41.40:45986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sionayra.tracybur.net"] [uri "/.git/config"] [unique_id "ap-L7nr71kFAhVn0tehlPgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-08 04:12:01
(3 hours ago)
Try to access /.git/config
Web App Attack