๐บ๐ธ
TPI-Abuse
2026-10-10 15:10:58
(6 minutes ago)
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 11:10:53.833014 2026] [security2:error] [pid 19021:tid 19021] [client 159.223.98.42:45906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "handyrehab.com"] [uri "/careers/.git/config"] [unique_id "aspVff9R0R16ezmWM5j-ZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-10 15:02:29
(15 minutes ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-10-10 14:50:07
(27 minutes ago)
159.223.98.42 - - [10/Oct/2026:22:50:06 +0800] "GET /jetso/.git/config HTTP/1.1" 200 11408 "-" "Mozi ...
show more
159.223.98.42 - - [10/Oct/2026:22:50:06 +0800] "GET /jetso/.git/config HTTP/1.1" 200 11408 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_3) AppleWebKit/534.55.3 (KHTML, like Gecko) Version/5.1.3 Safari/534.53.10"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
datajt
2026-10-10 14:43:38
(34 minutes ago)
Web vulnerability probing (CrowdSec scenario crowdsecurity/http-sensitive-files).
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 14:40:06
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 10:39:59.521889 2026] [security2:error] [pid 6124:tid 6124] [client 159.223.98.42:49844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greatchristianadventure.com"] [uri "/blog/.git/config"] [unique_id "aspOPzTDLbJAuLTCI6x04wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-10-10 14:24:15
(53 minutes ago)
2026/10/10 14:24:13 [error] 2003443#2003443: *37171362 access forbidden by rule, client: 159.223.98. ...
show more
2026/10/10 14:24:13 [error] 2003443#2003443: *37171362 access forbidden by rule, client: 159.223.98.42, server: finami.mx, request: "GET /affiliates/.git/config HTTP/2.0", host: "finami.mx"
2026/10/10 14:24:14 [error] 2003441#2003441: *37178481 access forbidden by rule, client: 159.223.98.42, server: finami.mx, request: "GET /contactos/.git/config HTTP/2.0", host: "finami.mx"
2026/10/10 14:24:14 [error] 2003444#2003444: *37181382 access forbidden by rule, client: 159.223.98.42, server: finami.es, request: "GET /contactos/.git/config HTTP/2.0", host: "finami.es"
...
show less
Web App Attack
๐บ๐ธ
etu brutus
2026-10-10 14:18:03
(59 minutes ago)
159.223.98.42 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐ฉ๐ช
london2038.com
2026-10-10 13:58:15
(1 hour ago)
Probing for exploits
159.223.98.42 - - [10/Oct/2026:15:58:11 +0200] "GET /t/.git/config HTTP/1.1" 42 ...
show more
Probing for exploits
159.223.98.42 - - [10/Oct/2026:15:58:11 +0200] "GET /t/.git/config HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.86 Safari/537.36"
159.223.98.42 - - [10/Oct/2026:15:58:11 +0200] "GET /u/.git/config HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Linux; Android 9; SM-G950F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 Mobile Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-10-10 13:52:05
(1 hour ago)
159.223.98.42 - - [10/Oct/2026:15:52:04 +0200] "GET /profile/.git/config HTTP/1.1" 403 180 "-" "Mozi ...
show more
159.223.98.42 - - [10/Oct/2026:15:52:04 +0200] "GET /profile/.git/config HTTP/1.1" 403 180 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 OPR/62.0.3331.119"
159.223.98.42 - - [10/Oct/2026:15:52:04 +0200] "GET /guidelines/.git/config HTTP/1.1" 403 118 "-" "Mozilla/5.0 (iPhone; U; CPU iPhone OS 4_2_1 like Mac OS X; da-dk) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8C148 Safari/6533.18.5"
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-10-10 13:50:49
(1 hour ago)
159.223.98.42 - - [10/Oct/2026:13:49:55 +0000] "GET /orientacio/.git/config HTTP/2.0" 403 48113 "-" ...
show more
159.223.98.42 - - [10/Oct/2026:13:49:55 +0000] "GET /orientacio/.git/config HTTP/2.0" 403 48113 "-" "Mozilla/5.0 (X11; Linux i686; rv:25.0) Gecko/20100101 Firefox/25.0" "159.223.98.42" edge="172.70.111.112"
159.223.98.42 - - [10/Oct/2026:13:49:56 +0000] "GET /localitat/.git/config HTTP/2.0" 403 48087 "-" "Mozilla/5.0 (Windows Phone 8.1; ARM; Trident/7.0; Touch; rv:11.0; IEMobile/11.0; NOKIA; Lumia 530) like Gecko" "159.223.98.42" edge="104.22.195.63"
159.223.98.42 - - [10/Oct/2026:13:49:56 +0000] "GET /javi2/.git/config HTTP/2.0" 403 48113 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows Phone OS 7.0; Trident/3.1; IEMobile/7.0) Asus;Galaxy6" "159.223.98.42" edge="172.70.111.112"
159.223.98.42 - - [10/Oct/2026:13:49:56 +0000] "GET /incidencies/.git/config HTTP/2.0" 403 48113 "-" "Mozilla/5.0 (X11; U; SunOS sun4m; en-US; rv:1.4b) Gecko/20030517 Mozilla Firebird/0.6" "159.223.98.42" edge="162.158.63.185"
159.223.98.42 - - [10/Oct/2026:13:49:56 +0000] "GET /csv/.git/config HTTP/2.0" 403 481
...
show less
Web App Attack
๐ช๐ธ
el-brujo
2026-10-10 13:50:18
(1 hour ago)
Cloudflare WAF: Request Path: /profile/.git/config Request Query: Host: forum.elhacker.net userAgen ...
show more
Cloudflare WAF: Request Path: /profile/.git/config Request Query: Host: forum.elhacker.net userAgent: Mozilla/5.0 (Linux; Android 9; SM-G950U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36 Action: block Source: firewallCustom ASN Description: DigitalOcean, LLC Country: US Method: GET Timestamp: 2026-10-10T13:50:18Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 13:32:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 159.223.98.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 09:31:54.830900 2026] [security2:error] [pid 4270:tid 4270] [client 159.223.98.42:41990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fluff3.instagenii.com"] [uri "/where2/.git/config"] [unique_id "aso-SgCxohBIqH21rsxcegAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-10-10 13:04:17
(2 hours ago)
Cloudflare WAF: Request Path: /windows/.git/config Request Query: Host: foro.elhacker.net userAgent ...
show more
Cloudflare WAF: Request Path: /windows/.git/config Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:49.0) Gecko/20100101 Firefox/49.0 Action: block Source: firewallCustom ASN Description: DigitalOcean, LLC Country: US Method: GET Timestamp: 2026-10-10T13:04:17Z ruleId: 6b2d48d0415e4adb9f099d85f54d1de6. Report generated by Cloudflare-WAF-to-AbuseIPDB.
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
Viveronese
2026-10-10 12:59:28
(2 hours ago)
HTTP vulnerability scanning
Web App Attack
๐ฉ๐ช
conseilgouz
2026-10-10 12:17:21
(3 hours ago)
ece-17 : Block hidden directories=>/elevage/.git/config(/)
Hacking