๐ต๐ฑ
mkey
2026-09-01 09:11:44
(18 hours ago)
[First: 2026-08-31 22:00:58/single] HITS=1 Sensitive file probing; sample=GET /.git/config 404
Port Scan
Hacking
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-01 05:22:48
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐ง๐ท
Peregrine
2026-09-01 04:50:30
(23 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.103.37 172.68.34.187 - - [01/Sep/2026:01:50:27 -0 ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: 144.172.103.37 172.68.34.187 - - [01/Sep/2026:01:50:27 -0300] "GET /.git/config HTTP/1.1" 404 414
show less
Bad Web Bot
๐จ๐ญ
4server
2026-09-01 04:18:20
(23 hours ago)
[TueSep0106:18:17.4209952026][security2:error][pid1674226:tid1674539][client144.172.103.37:0]ModSecu ...
show more
[TueSep0106:18:17.4209952026][security2:error][pid1674226:tid1674539][client144.172.103.37:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"shakary.com\"][uri\"/.git/config\"][unique_id\"apZSCetUtHW6SXlrRqGOYgAAAJI\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:11:40
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6725::90ac:6725 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6725::90ac:6725 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:11:31.923172 2026] [security2:error] [pid 11104:tid 11104] [client 2002:90ac:6725::90ac:6725:61897] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "janeeyreillustrated.com"] [uri "/.git/config"] [unique_id "apZQcyN8KYFuvKXPidJLIgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
internetworld
2026-09-01 03:55:55
(23 hours ago)
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from interne ...
show more
internetworld-prod-01 Fail2Ban ban. Jail=nginx-web-probe-iw. Sanitized automatic report from internetworld.ca server security monitoring.
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-01 03:43:19
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:34:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 144.172.103.37 (37.103.172.144.static.cloudzy.c ...
show more
(mod_security) mod_security (id:210492) triggered by 144.172.103.37 (37.103.172.144.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:34:20.032044 2026] [security2:error] [pid 7315:tid 7315] [client 144.172.103.37:17511] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "huboon.com"] [uri "/.git/config"] [unique_id "apY5rMQagUaKkUZRZlJvvQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-09-01 02:28:36
(1 day ago)
Honeypot access: Git configuration file access attempt. Path: /.git/config
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-01 02:20:16
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:31:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6725::90ac:6725 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2002:90ac:6725::90ac:6725 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:31:05.166414 2026] [security2:error] [pid 3275:tid 3275] [client 2002:90ac:6725::90ac:6725:35037] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fancyspider.net"] [uri "/.git/config"] [unique_id "apYq2b5CYfblyovI8zp47wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Smish
2026-09-01 01:28:05
(1 day ago)
HONEYPOT HIT --> Fail2ban time=1788226084 log=2026-09-01T02:28:04+01:00 ip=144.172.103.37 host=as210 ...
show more
HONEYPOT HIT --> Fail2ban time=1788226084 log=2026-09-01T02:28:04+01:00 ip=144.172.103.37 host=as210667.net method=GET uri="/.git/config" status=404 ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36" ref="-" rid=83145227568ed7dfdea5c3f0252b6e0a
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-01 01:08:01
(1 day ago)
Fail2Ban - [WEB]Exploit attempts (SQLi, RCE, path traversal) on webexploits ... [ice01,ice02,wa01]
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 00:01:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-08-31 23:55:06
(1 day ago)
144.172.103.37 - - [31/Aug/2026:20:55:03 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 ( ...
show more
144.172.103.37 - - [31/Aug/2026:20:55:03 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host