๐ฉ๐ช
initsol
2026-09-22 14:32:11
(4 days ago)
[Tue Sep 22 15:59:44.930009 2026] [authz_core:error] [pid 575849:tid 575849] [client 143.244.173.125 ...
show more
[Tue Sep 22 15:59:44.930009 2026] [authz_core:error] [pid 575849:tid 575849] [client 143.244.173.125:36926] AH01630: client denied by server configuration: /var/www/.git
[Tue Sep 22 16:27:22.249694 2026] [authz_core:error] [pid 624757:tid 624757] [client 143.244.173.125:36528] AH01630: client denied by server configuration: /var/www/.git
[Tue Sep 22 16:32:11.575977 2026] [authz_core:error] [pid 575849:tid 575849] [client 143.244.173.125:55264] AH01630: client denied by server configuration: /var/www/.git
...
show less
Brute-Force
๐ซ๐ฎ
oh.mg
2026-09-22 09:56:39
(4 days ago)
[Tue Sep 22 11:56:39.249454 2026] [security2:error] [pid 2116937:tid 2116939] [client 143.244.173.12 ...
show more
[Tue Sep 22 11:56:39.249454 2026] [security2:error] [pid 2116937:tid 2116939] [client 143.244.173.125:48130] [client 143.244.173.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.git/config"] [unique_id "arJQ12J4SddqHbNsHYf2NwAAAAA"]
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-09-22 05:48:01
(4 days ago)
[Tue Sep 22 07:48:00.564907 2026] [security2:error] [pid 1897495:tid 1897520] [client 143.244.173.12 ...
show more
[Tue Sep 22 07:48:00.564907 2026] [security2:error] [pid 1897495:tid 1897520] [client 143.244.173.125:43930] [client 143.244.173.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.git/config"] [unique_id "arIWkOtrsYJ3O_L0g6RYeAAAAFc"]
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-09-22 05:37:09
(4 days ago)
Blocked by firewall on hugin [80/tcp] | Rule: AbuseIPDB | SPT: 39584 | TTL: 57 | LEN: 60 | TOS: 0x00 ...
show more
Blocked by firewall on hugin [80/tcp] | Rule: AbuseIPDB | SPT: 39584 | TTL: 57 | LEN: 60 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐น๐ผ
tyebstx
2026-09-22 03:48:13
(4 days ago)
Wazuh Alert Evidence: 143.244.173.125 - - [22/Sep/2026:03:48:09 +0000] "GET /.git/config HTTP/1.1" 4 ...
show more
Wazuh Alert Evidence: 143.244.173.125 - - [22/Sep/2026:03:48:09 +0000] "GET /.git/config HTTP/1.1" 403 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-"
show less
Web App Attack
๐ท๐ธ
pexodelic
2026-09-22 03:35:01
(4 days ago)
Automated report from web, SSH and FTP server logs: 6 requests probing for exposed secrets (.env, .g ...
show more
Automated report from web, SSH and FTP server logs: 6 requests probing for exposed secrets (.env, .git, config files). First reported 2026-09-22 05:05 UTC, last reported 2026-09-22 05:35 UTC; counts cover the current log rotation window.
show less
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-22 03:16:42
(5 days ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 2 domain(s) in -1s
Web App Attack
๐ง๐ช
webbie
2026-09-22 02:26:24
(5 days ago)
143.244.173.125 - - [22/Sep/2026:00:15:46 +0200] "GET /.git/config HTTP/1.1" 404 437 "-" "Mozilla/5. ...
show more
143.244.173.125 - - [22/Sep/2026:00:15:46 +0200] "GET /.git/config HTTP/1.1" 404 437 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
143.244.173.125 - - [22/Sep/2026:00:15:46 +0200] "GET /.git/config HTTP/1.1" 404 5276 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
143.244.173.125 - - [22/Sep/2026:01:34:11 +0200] "GET /.git/config HTTP/1.1" 404 437 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
143.244.173.125 - - [22/Sep/2026:01:34:11 +0200] "GET /.git/config HTTP/1.1" 404 5276 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
143.244.173.125 - - [22/Sep/2026:04:26:21 +0200] "GET /.git/config HTTP/1.1" 404 437 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:53:06
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:53:00.132440 2026] [security2:error] [pid 23241:tid 23241] [client 143.244.173.125:42424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.235"] [uri "/.git/config"] [unique_id "arHRbHotreXb8ceNmFQvXgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sdos.es
2026-09-22 00:25:28
(5 days ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
Anonymous
2026-09-22 00:11:03
(5 days ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:43:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:43:33.117681 2026] [security2:error] [pid 11747:tid 11747] [client 143.244.173.125:52020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.139"] [uri "/.git/config"] [unique_id "arHBJbDu94xjvkQ5vWujgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:01:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 143.244.173.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:01:10.766585 2026] [security2:error] [pid 706:tid 706] [client 143.244.173.125:35844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.168"] [uri "/.git/config"] [unique_id "arG3NnXVYUvc42uJGhsCggAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
seanwall
2026-09-21 22:39:36
(5 days ago)
Automated scanner/attacker probing war-room. Paths: ['/.git/config', '/.git/config']. UA: ['Mozilla/ ...
show more
Automated scanner/attacker probing war-room. Paths: ['/.git/config', '/.git/config']. UA: ['Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36']
show less
Port Scan
Bad Web Bot
Web App Attack
๐ซ๐ฎ
oh.mg
2026-09-21 22:34:45
(5 days ago)
[Tue Sep 22 00:34:44.771901 2026] [security2:error] [pid 1897523:tid 1897541] [client 143.244.173.12 ...
show more
[Tue Sep 22 00:34:44.771901 2026] [security2:error] [pid 1897523:tid 1897541] [client 143.244.173.125:56868] [client 143.244.173.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "95.216.72.247"] [uri "/.git/config"] [unique_id "arGxBBBQ9dFeJh2yLZmb2QAAARA"]
[Tue Sep 22 00:34:45.141858 2026] [security2:error] [pid 1897495:tid 1897506] [client 143.244.173.125:60934] [client 143.244.173.125] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.10
...
show less
Web App Attack
Bad Web Bot