๐จ๐ญ
YF
2026-10-02 01:37:13
(18 minutes ago)
Git config exposure probe
Web App Attack
๐ฉ๐ช
4server
2026-10-01 23:46:59
(2 hours ago)
[FriOct0201:46:52.9661552026][security2:error][pid1587844:tid1587915][client157.245.136.170:0]ModSec ...
show more
[FriOct0201:46:52.9661552026][security2:error][pid1587844:tid1587915][client157.245.136.170:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"simireinigung.ch\"][uri\"/.git/config\"][unique_id\"ar7w7InXcg_RSzX_WFKs2gAAAFY\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-10-01 22:44:02
(3 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-10-01 20:50:53
(5 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 19:27:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 15:27:26.312321 2026] [security2:error] [pid 6495:tid 6567] [client 157.245.136.170:56288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pyro-one.com"] [uri "/.git/config"] [unique_id "ar60HhSUDVdynwKHS0A9XAAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-01 19:05:45
(6 hours ago)
Abuse Detected (22)
Brute-Force
Web App Attack
๐บ๐ธ
craudiovizai
2026-10-01 18:30:34
(7 hours ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked a ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/config. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 17:07:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:07:11.826282 2026] [security2:error] [pid 31717:tid 31717] [client 157.245.136.170:47750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dosfordogs.ca"] [uri "/.git/config"] [unique_id "ar6TP3F4WVTvV_69n7_o0QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:18:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:18:40.765324 2026] [security2:error] [pid 9041:tid 9041] [client 157.245.136.170:44634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stortfordmedical.com"] [uri "/.git/config"] [unique_id "ar6H4KN1sGfIy0wMYsaS3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:56:53
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:56:46.968189 2026] [security2:error] [pid 26810:tid 26810] [client 157.245.136.170:36854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jchiggins.com"] [uri "/.git/config"] [unique_id "ar6CvkHlSL-n61hxKk7NlQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:17:23
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:17:18.696920 2026] [security2:error] [pid 25172:tid 25172] [client 157.245.136.170:53576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elenius.com"] [uri "/.git/config"] [unique_id "ar55ftItMuwyQ3jkM7TxHgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:31:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:31:15.615543 2026] [security2:error] [pid 30869:tid 30869] [client 157.245.136.170:33610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phillatwood.com"] [uri "/.git/config"] [unique_id "ar5us9r0vfTF4Gll324rvwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:33:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:33:33.223043 2026] [security2:error] [pid 5894:tid 5894] [client 157.245.136.170:45948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "snowfection.com"] [uri "/.git/config"] [unique_id "ar5hLYNP_tNVGPk5TMDThwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-01 13:33:22
(12 hours ago)
[ThuOct0115:33:17.7793232026][security2:error][pid3699936:tid3699962][client157.245.136.170:0]ModSec ...
show more
[ThuOct0115:33:17.7793232026][security2:error][pid3699936:tid3699962][client157.245.136.170:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"ristrutturazione-case.ch\"][uri\"/.git/config\"][unique_id\"ar5hHbwYqc93QjMjPixVeAAAANg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:55:06
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 157.245.136.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:55:01.706747 2026] [security2:error] [pid 17752:tid 17752] [client 157.245.136.170:50432] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "saniyadenton.click"] [uri "/.git/config"] [unique_id "ar5YJRrphu1jNmxJe3yJtAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack