๐ช๐ธ
el-brujo
2025-11-30 03:02:58
(7 months ago)
30/Nov/2025:04:02:58.206758 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
30/Nov/2025:04:02:58.206758 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 159.203.136.234] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.git/config"] [unique_id "aSuz4kn4It-uSFEtzfCQSwALEic"]
...
show less
Hacking
Web App Attack
Anonymous
2025-11-30 01:27:38
(7 months ago)
(mod_security) mod_security triggered on hostname [redacted] 159.203.136.234 (US/United States/-)
SQL Injection
๐ฌ๐ง
[email protected]
2025-11-30 00:45:50
(7 months ago)
...
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2025-11-29 23:04:49
(7 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-11-28.
show less
Hacking
Web App Attack
SSH
๐ช๐ธ
el-brujo
2025-11-29 21:31:41
(7 months ago)
29/Nov/2025:22:31:40.332039 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Nov/2025:22:31:40.332039 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 159.203.136.234] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.git/config"] [unique_id "aStmPG4gPudWN4n9AIQptgAEFg8"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2025-11-29 21:05:40
(7 months ago)
Too many Status 40X (30)
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2025-11-29 19:46:43
(7 months ago)
29/Nov/2025:20:46:42.821068 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
29/Nov/2025:20:46:42.821068 +0100Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 159.203.136.234] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.git/config"] [unique_id "aStNoqyNsNctgqWK8yM9lAAHFw0"]
...
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2025-11-29 17:56:55
(7 months ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ง๐ช
Ivo Vynckier
2025-11-29 16:21:00
(7 months ago)
159.203.136.234 - - [29/Nov/2025:16:12:09 +0100] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5. ...
show more
159.203.136.234 - - [29/Nov/2025:16:12:09 +0100] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Web App Attack
๐ง๐ช
madeit
2025-11-29 14:23:06
(7 months ago)
Web App Attack
๐ฉ๐ช
juutis
2025-11-29 14:14:22
(7 months ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2025-11-29 06:14:07
(7 months ago)
5 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ซ๐ท
masterguru
2025-11-29 06:07:56
(7 months ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-29 05:52:06
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 159.203.136.234 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 159.203.136.234 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 00:51:59.703526 2025] [security2:error] [pid 1172:tid 1172] [client 159.203.136.234:47158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icesoft.blog"] [uri "/.git/config"] [unique_id "aSqJ_4YAoO6SJ2anQerNdQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2025-11-29 04:55:40
(7 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Hacking
Web App Attack