๐บ๐ธ
TIScore
2026-08-22 22:29:22
(17 hours ago)
Automated web attack / probing. Signals: Secret / VCS probing; Unexpected path. Last path: /.git/con ...
show more
Automated web attack / probing. Signals: Secret / VCS probing; Unexpected path. Last path: /.git/config
show less
Web App Attack
๐ฉ๐ช
4server
2026-08-22 21:27:12
(18 hours ago)
[SatAug2223:27:10.3483742026][security2:error][pid2972097:tid2972215][client170.64.190.169:0]ModSecu ...
show more
[SatAug2223:27:10.3483742026][security2:error][pid2972097:tid2972215][client170.64.190.169:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"wildpferde.ch\"][uri\"/.git/config\"][unique_id\"aooULkMQ7g5qiAEjnA-s_gAAAQY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
Inartis
2026-08-22 21:15:46
(18 hours ago)
170.64.190.169 - - [22/Aug/2026:21:59:15 +0200] "GET /.git/config HTTP/1.1" 302 513 "-" "Mozilla/5.0 ...
show more
170.64.190.169 - - [22/Aug/2026:21:59:15 +0200] "GET /.git/config HTTP/1.1" 302 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.190.169 - - [22/Aug/2026:21:59:20 +0200] "GET /.git/config HTTP/1.1" 404 47160 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
170.64.190.169 - - [22/Aug/2026:23:15:44 +0200] "GET /.git/config HTTP/1.1" 302 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-08-22 18:55:19
(20 hours ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-22 18:49:47
(20 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-22 14:45:37
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-22 12:12:15
(1 day ago)
Web vulnerability probing: /.git/config
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-22 12:03:26
(1 day ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 2 domain(s) in 2s
Web App Attack
๐ธ๐ช
SkyDancer
2026-08-22 11:56:01
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-22 09:15:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:15:20.848508 2026] [security2:error] [pid 28748:tid 28748] [client 170.64.190.169:37022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tankercontrol.com"] [uri "/.git/config"] [unique_id "aoloqGFgAvWvNKbq_R8qiQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 07:31:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:31:34.978949 2026] [security2:error] [pid 1571:tid 1597] [client 170.64.190.169:43018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ewoolsey.com"] [uri "/.git/config"] [unique_id "aolQViVXkdMClu8lopC3wQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 06:32:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.190.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:32:07.933497 2026] [security2:error] [pid 5724:tid 5724] [client 170.64.190.169:41568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "247.fishing"] [uri "/.git/config"] [unique_id "aolCZ-6eXX1ikqdnoLp-EAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-22 06:19:43
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ณ๐ฑ
MM-bot
2026-08-22 06:00:43
(1 day ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-08-22 08:00:43 UTC+2)
Web App Attack
Hacking
๐ฌ๐ง
openstrike.co.uk
2026-08-22 05:15:11
(1 day ago)
3 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking