๐ฟ๐ฆ
conure.sh
2026-08-23 12:11:04
(14 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐น๐ท
oalver
2026-08-23 00:53:42
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.git/config (HTTP 301). First seen: 2026-08-21. Risk score: 100/100.
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-22 20:07:54
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
Baking333
2026-08-22 19:52:54
(1 day ago)
[redacted] 170.64.223.50 - - [22/Aug/2026:20:52:51 +0100] "GET /.git/config HTTP/1.1" 301 596 0/69 " ...
show more
[redacted] 170.64.223.50 - - [22/Aug/2026:20:52:51 +0100] "GET /.git/config HTTP/1.1" 301 596 0/69 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" [redacted] 170.64.223.50 - - [22/Aug/2026:20:52:53 +0100] "GET /.git/config HTTP/1.1" 302 6798 0/58167 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐น๐ท
oalver
2026-08-22 13:18:16
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.git/config (HTTP 301). First seen: 2026-08-21. Risk score: 90/100.
show less
Web App Attack
๐ซ๐ฎ
YF
2026-08-22 12:00:31
(1 day ago)
Git config exposure probe
Web App Attack
๐ต๐ฑ
Budyn
2026-08-22 11:29:48
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.top | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:24:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:24:10.762240 2026] [security2:error] [pid 10631:tid 10631] [client 170.64.223.50:41218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gonzalezmultiservicios.com"] [uri "/.git/config"] [unique_id "aol4yvwwcwuYHcwK2iPIdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:38:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:37:57.655221 2026] [security2:error] [pid 31957:tid 32009] [client 170.64.223.50:47832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "econpage.com"] [uri "/.git/config"] [unique_id "aolt9S7oB7Cam0yVD__UxQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-22 08:57:59
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-22 08:34:13
(1 day ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 07:22:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:22:16.673767 2026] [security2:error] [pid 22821:tid 22821] [client 170.64.223.50:34860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accredo.net"] [uri "/.git/config"] [unique_id "aolOKMk3FNewZNa0fNRF7wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 06:47:26
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:949110) triggered by 170.64.223.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 02:47:18.599221 2026] [security2:error] [pid 17272:tid 17272] [client 170.64.223.50:55428] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "alliancegroupga.com"] [uri "/.git/config"] [unique_id "aolF9vZ9hRDtgWkh37-RAQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-08-22 05:22:34
(1 day ago)
[redacted] 170.64.223.50 - - [22/Aug/2026:06:22:31 +0100] "GET /.git/config HTTP/1.1" 301 596 0/171 ...
show more
[redacted] 170.64.223.50 - - [22/Aug/2026:06:22:31 +0100] "GET /.git/config HTTP/1.1" 301 596 0/171 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" [redacted] 170.64.223.50 - - [22/Aug/2026:06:22:32 +0100] "GET /.git/config HTTP/1.1" 302 6798 0/41482 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-22 05:15:15
(1 day ago)
4 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking