π³π΄
jad-abuse
2026-07-20 21:33:27
(6 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 6 hits.
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 18:58:20
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:58:15.825442 2026] [security2:error] [pid 13318:tid 13318] [client 157.52.92.77:17686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "taekwondoit.com"] [uri "/.git/config"] [unique_id "al5vx_VjoS5Hz_DeflZ4iQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 18:31:04
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:30:56.057378 2026] [security2:error] [pid 15900:tid 15909] [client 157.52.92.77:62838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.writeonce.org"] [uri "/.git/HEAD"] [unique_id "al5pYGLdkoqb9F3dPuxSQwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-07-20 17:48:04
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 17:32:52
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:32:46.751174 2026] [security2:error] [pid 18892:tid 18892] [client 157.52.92.77:2480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qbasys.com"] [uri "/.git/HEAD"] [unique_id "al5bvi-Zf8g44kya7m4pJQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 16:19:52
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 12:19:45.914587 2026] [security2:error] [pid 10925:tid 10925] [client 157.52.92.77:35826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.jfhglobal.net"] [uri "/.git/config"] [unique_id "al5KoVsK2MXHilqmmJ3ByAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
tmiland
2026-07-20 14:39:42
(13 hours ago)
(nginx_404) Dot directory Honeypot Trap 157.52.92.77 (SG/Singapore/-): 2 in the last 3600 secs; IP: ...
show more
(nginx_404) Dot directory Honeypot Trap 157.52.92.77 (SG/Singapore/-): 2 in the last 3600 secs; IP: 157.52.92.77; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 157.52.92.77 - - [20/Jul/2026:16:39:36 +0200] "GET /.git/config HTTP/1.1" 404 68204 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0" 157.52.92.77 - - [20/Jul/2026:16:39:37 +0200] "GET /.git/HEAD HTTP/1.1" 404 68204 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:126.0) Gecko/20100101 Firefox/126.0"
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-20 11:56:25
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:56:18.859943 2026] [security2:error] [pid 18430:tid 18430] [client 157.52.92.77:51310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.newfedco.com"] [uri "/.git/config"] [unique_id "al4M4p2VVHLT1VT6uPQHTgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 05:51:16
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 01:51:11.062064 2026] [security2:error] [pid 7127:tid 7127] [client 157.52.92.77:37516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.vittariahealth.com"] [uri "/.git/HEAD"] [unique_id "al23T5SwqYeETmAZK49E-gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 05:51:02
(22 hours ago)
157.52.92.77 - - [20/Jul/2026:07:51:02 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ( ...
show more
157.52.92.77 - - [20/Jul/2026:07:51:02 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
show less
Web App Attack
π©πͺ
big-cloud.nl
2026-07-20 00:51:03
(1 day ago)
Try to access /.git/HEAD
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-07-20 00:37:07
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-iad5-2)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 21:49:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 17:49:51.590661 2026] [security2:error] [pid 5201:tid 5249] [client 157.52.92.77:45594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.robertbellamy.com"] [uri "/.git/HEAD"] [unique_id "al1Gf40oRxa2P9j-qxqDdAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 21:08:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 17:08:48.175896 2026] [security2:error] [pid 4060774:tid 4060774] [client 157.52.92.77:22868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gatheringsattheschool.com"] [uri "/.git/HEAD"] [unique_id "al084Alwffc0Xp6e9_zM9wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-19 20:15:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 157.52.92.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 16:15:32.922032 2026] [security2:error] [pid 10739:tid 10739] [client 157.52.92.77:57104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.clustershow.com"] [uri "/.git/config"] [unique_id "al0wZH4-DFfr1R-RFnMONQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack