๐ณ๐ฑ
homeshowdomain.nl
2026-08-26 21:59:34
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-25.
show less
Web App Attack
SSH
Hacking
๐ง๐ช
Ivo Vynckier
2026-08-26 12:34:00
(1 day ago)
167.99.158.181 - - [26/Aug/2026:00:22:09 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ...
show more
167.99.158.181 - - [26/Aug/2026:00:22:09 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Web App Attack
๐ง๐ท
dominioz
2026-08-26 11:58:51
(1 day ago)
2026-08-26 11:58:24 GET /.git/config - - 167.99.158.181 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+App ...
show more
2026-08-26 11:58:24 GET /.git/config - - 167.99.158.181 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 475
2026-08-26 11:58:26 GET /.git/config - - 167.99.158.181 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 586
2026-08-26 11:58:26 GET /.git/config - - 167.99.158.181 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/81.0.4044.129+Safari/537.36 - 301 586
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:46:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:46:36.285711 2026] [security2:error] [pid 24759:tid 24759] [client 167.99.158.181:47526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intrialconsultants.com"] [uri "/.git/config"] [unique_id "ao7EDIMTQijJeBUu4eJfgwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 09:10:06
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-08-26 08:05:05
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-08-26 07:01:36
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: budyn.wtf | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-26 06:08:08
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-http-sensitive-files.
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-26 05:16:09
(1 day ago)
4 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
Anonymous
2026-08-26 05:15:02
(1 day ago)
File repository snooping:
167.99.158.181 - - [26/Aug/2026:06:02:20 +0100] "GET /.git/config HTTP/1. ...
show more
File repository snooping:
167.99.158.181 - - [26/Aug/2026:06:02:20 +0100] "GET /.git/config HTTP/1.1" 404 330 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 05:09:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 01:09:29.355202 2026] [security2:error] [pid 10531:tid 10531] [client 167.99.158.181:53048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeramps.com"] [uri "/.git/config"] [unique_id "ao51CfJC1pi8GOZeOCj4rgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-26 02:25:20
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 01:59:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.99.158.181 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 21:59:26.140166 2026] [security2:error] [pid 4379:tid 4379] [client 167.99.158.181:48852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elianabeam.com"] [uri "/.git/config"] [unique_id "ao5IfqwB1rxjEnNa5SvcvQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
informedclearly.com
2026-08-25 23:01:01
(1 day ago)
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.git/config? ua=Mozilla/5.0 (X11; Linux x86_64) ...
show more
WAF_BAN reason=ENV_PROBE rule=ENV_PATH hits=1 path=/.git/config? ua=Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36
show less
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-25 21:59:49
(1 day ago)
Auto-ban: >3000 req/min op 2026-08-25
Web App Attack
SSH
Hacking