🇺🇸
stdcout9090
2026-09-07 03:56:03
(16 minutes ago)
AetherGuard WAF blocked: Matched phrase "/.git/" at REQUEST_URI.
Target: management.aetherguard.xyz/ ...
show more
AetherGuard WAF blocked: Matched phrase "/.git/" at REQUEST_URI.
Target: management.aetherguard.xyz/.git/config
Payload / matched WAF rule data:
User-Agent: Mozilla/5.0 (X11; Linux x86_64)
show less
Web App Attack
🇫🇷
arsonist
2026-09-07 03:08:33
(1 hour ago)
[fail2ban]
2026-09-07T03:08:32.599851+00:00 arson caddy[1890453]: {"level":"info","ts":1788750512.59 ...
show more
[fail2ban]
2026-09-07T03:08:32.599851+00:00 arson caddy[1890453]: {"level":"info","ts":1788750512.599823,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"136.66.190.23","remote_port":"45480","client_ip":"136.66.190.23","proto":"HTTP/1.1","method":"GET","host":"mc.possum.city","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64)"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"mc.possum.city","ech":false}},"bytes_read":0,"user_id":"","duration":0.000082255,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇺🇸
Rip
2026-09-07 03:07:28
(1 hour ago)
Restricted File Access Attempts
Port Scan
Web App Attack
Anonymous
2026-09-07 03:07:07
(1 hour ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-07 03:04:24.
Web App Attack
🇺🇸
mnsf
2026-09-07 03:05:38
(1 hour ago)
Abuse Detected (53)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:59:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.190.23 (23.190.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.190.23 (23.190.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:59:16.056122 2026] [security2:error] [pid 14766:tid 14766] [client 136.66.190.23:44534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sipa.com.hk"] [uri "/.git/config"] [unique_id "ap4ohIVMVMmU4J5Tz5EPuAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Major Hostility
2026-09-07 02:57:13
(1 hour ago)
"GET /.git/config HTTP/1.1" 404
"GET /.git/config HTTP/1.1" 404
Web App Attack
🇩🇪
ghostwarriors
2026-09-07 02:50:09
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇫🇷
LRob
2026-09-07 02:47:39
(1 hour ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.git/config | 2026-09-07 02:47 UTC
show less
Hacking
Web App Attack
🇺🇸
Charlesiv
2026-09-07 02:46:28
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-07T02:11:25Z
Ray ID: a3722ec49ad275ae
UA: Mozilla/5.0 (X11; Linux x86_64)
show less
Bad Web Bot
🇩🇪
yitzhaq
2026-09-07 02:45:37
(1 hour ago)
136.66.190.23 - - [07/Sep/2026:04:45:34 +0200] "GET /.git/config HTTP/1.1" 403 4406 "-" "Mozilla/5.0 ...
show more
136.66.190.23 - - [07/Sep/2026:04:45:34 +0200] "GET /.git/config HTTP/1.1" 403 4406 "-" "Mozilla/5.0 (X11; Linux x86_64)"
136.66.190.23 - - [07/Sep/2026:04:00:48 +0200] "GET /.git/config HTTP/1.1" 403 4447 "-" "Mozilla/5.0 (X11; Linux x86_64)"
136.66.190.23 - - [07/Sep/2026:04:35:37 +0200] "GET /.git/config HTTP/1.1" 403 4435 "-" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Web App Attack
Hacking
🇩🇪
ITSNF
2026-09-07 02:45:04
(1 hour ago)
Blocked by os-abuseipdb; 4 hits, proto=tcp, ports=443
Port Scan
Hacking
Anonymous
2026-09-07 02:44:03
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-09-07 02:43:13
(1 hour ago)
Scanner hitting /.git/config on livekit.osef.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 02:41:15
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.66.190.23 (23.190.66.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 136.66.190.23 (23.190.66.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:41:09.859626 2026] [security2:error] [pid 11127:tid 11127] [client 136.66.190.23:54900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "limocorpuschristi.com"] [uri "/.git/config"] [unique_id "ap4kRbkUQGw9T9Y1vR1UywAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack