๐บ๐ธ
OceanTreasure
2026-09-26 22:39:43
(9 hours ago)
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs? ...
show more
tcp/443; Git smart-HTTP repository clone attempt against an exposed .git directory (/.git/info/refs?service=git-upload-pack): "GET /.git/info/refs?service=git-upload-pack" @ 2026-09-26T22:39:43Z [proxy]
show less
Web App Attack
๐บ๐ธ
ricw
2026-09-25 16:09:39
(1 day ago)
[Phylax Security Report] Type: Web Exploit & Vulnerability Probe
Source IP: 172.105.158.117
Endpoint ...
show more
[Phylax Security Report] Type: Web Exploit & Vulnerability Probe
Source IP: 172.105.158.117
Endpoint: GET /.git/info/refs
Timestamp: 1790352579213 ms
Notes: Phylax autonomous decoy URI probe trapped on path '/.git/info/refs' (Version Control Repository Probe)
User-Agent: git/2.43.0
Forensic validation: Automated probe detected by deterministic application defense.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:21:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:21:04.727119 2026] [security2:error] [pid 2978:tid 2978] [client 172.105.158.117:47564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgweich.com"] [uri "/.git/info/refs"] [unique_id "arVqEFIrOsMjG-mOK0REewAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-23 09:08:01
(3 days ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02,wa01,wa02]
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-23 07:42:02
(4 days ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa02]
Hacking
SQL Injection
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:23:07
(4 days ago)
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 172.105.158.117 - - [22/Sep/2026:16:22:59 +0200] "GET /.git/info/refs?service=git-upload-pack HTTP/2.0" 301 401 "-" "git/2.43.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:00:55
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:00:50.185273 2026] [security2:error] [pid 18326:tid 18326] [client 172.105.158.117:57492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "edwardchrisman.com"] [uri "/.git/info/refs"] [unique_id "arJR0nebnnPhRzqKLRGPsgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:38:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:38:36.225599 2026] [security2:error] [pid 22783:tid 22783] [client 172.105.158.117:58082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wadenelson.com"] [uri "/.git/info/refs"] [unique_id "arI-jEPaStU_PBk1C8Qo2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 16:05:18
(5 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 10:34:19
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:34:13.574952 2026] [security2:error] [pid 26542:tid 26542] [client 172.105.158.117:46012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kbalan.com"] [uri "/.git/info/refs"] [unique_id "arEIJcflY-nWusLbgwRzkwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
craudiovizai
2026-09-20 06:30:42
(1 week ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/info/refs. Blocke ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /.git/info/refs. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-19 18:17:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:17:44.373429 2026] [security2:error] [pid 10622:tid 10622] [client 172.105.158.117:55634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "market1st.com"] [uri "/.git/info/refs"] [unique_id "aq7RyM3mHN4UvGfu2YzlxwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 07:12:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 03:12:25.299272 2026] [security2:error] [pid 3111:tid 3111] [client 172.105.158.117:40720] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lucasadams.com"] [uri "/.git/info/refs"] [unique_id "aq412ZtK1lezjNa804FMjAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 06:22:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 172.105.158.117 (172-105-158-117.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 02:21:59.997518 2026] [security2:error] [pid 23907:tid 23907] [client 172.105.158.117:60020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wglennburns.com"] [uri "/.git/info/refs"] [unique_id "aq4qBz7wQSAae_aMgFV8_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-17 14:05:16
(1 week ago)
Abuse Detected (9)
Brute-Force
Web App Attack