πΊπΈ
COMPLEX
2025-06-22 01:21:22
(1 year ago)
Honeypot [1]: HTTP/1.1 request on 14000
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebK ...
show more
Honeypot [1]: HTTP/1.1 request on 14000
GET /
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/137.0.0.0 Safari/537.36
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate; 14000 [2] TCP
show less
Web App Attack
πΊπΈ
MPL
2025-06-22 01:08:37
(1 year ago)
tcp/5552 (2 or more attempts)
Port Scan
πΉπ·
rtbh.com.tr
2025-03-04 20:49:15
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
π§πͺ
sid3windr
2025-03-04 20:10:13
(1 year ago)
GET /.git/config (Tarpitted for 1d15h8m29s, wasted 8.06MB)
Web App Attack
π§πͺ
sid3windr
2025-03-04 16:57:30
(1 year ago)
GET /.git/config (Tarpitted for 1d15h8m25s, wasted 8.06MB)
Web App Attack
πΉπ·
rtbh.com.tr
2025-03-04 04:49:16
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
πΉπ·
rtbh.com.tr
2025-03-03 20:49:17
(1 year ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
Anonymous
2025-03-03 15:14:50
(1 year ago)
Fail2Ban Log Report 159.203.59.37 - [03/Mar/2025:16:14:48 +0100] "GET /.git/config HTTP/1.1" 301 162 ...
show more
Fail2Ban Log Report 159.203.59.37 - [03/Mar/2025:16:14:48 +0100] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "-" "-"
...
show less
Hacking
SQL Injection
Web App Attack
π©πͺ
alliance
2025-03-03 14:31:04
(1 year ago)
03.03.2025 14:31:04 Git repository scan (/.git)
Hacking
Web App Attack
πΊπΈ
vestibtech
2025-03-03 14:14:54
(1 year ago)
159.203.59.37 - - [03/Mar/2025:07:14:53 -0700] "GET /.git/config HTTP/1.1" 300 3523 "-" "Mozilla/5.0 ...
show more
159.203.59.37 - - [03/Mar/2025:07:14:53 -0700] "GET /.git/config HTTP/1.1" 300 3523 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Web App Attack
π«π·
dynamix
2025-03-03 13:46:50
(1 year ago)
Multiple WAF Violations
Web App Attack
π¨π¦
yukon.ca
2025-03-03 12:58:14
(1 year ago)
Web Server Enforcement Violation: Web Server Exposed Git Repository Information Disclosure
Port:80
Hacking
Exploited Host
πΊπΈ
TPI-Abuse
2025-03-03 12:30:39
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 07:30:31.036768 2025] [security2:error] [pid 23940:tid 23940] [client 159.203.59.37:55162] [client 159.203.59.37] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.110"] [uri "/.git/config"] [unique_id "Z8Wg5-0myjFUnrYG5UjatgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-03 11:55:03
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 06:54:56.112716 2025] [security2:error] [pid 1490952:tid 1490952] [client 159.203.59.37:50286] [client 159.203.59.37] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.61"] [uri "/.git/config"] [unique_id "Z8WYkEJ3NdZttUgQCWzscQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-03-03 11:09:40
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.203.59.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 03 06:09:34.696301 2025] [security2:error] [pid 14422:tid 14614] [client 159.203.59.37:49546] [client 159.203.59.37] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.80"] [uri "/.git/config"] [unique_id "Z8WN7qFKuP1erO4-DE9ngAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack