Anonymous
2026-09-09 23:29:29
(13 minutes ago)
Scan for .git Files at 2026-09-09T23:29:29+00:00
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 23:23:37
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:23:29.219787 2026] [security2:error] [pid 7695:tid 7695] [client 172.86.74.236:39816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.intelligencer.us"] [uri "/.git/config"] [unique_id "aqHqcQCcAH5JhhZZejDvVQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-09 23:00:26
(42 minutes ago)
Git config exposure probe
Web App Attack
🇩🇪
paissangroup
2026-09-09 22:40:22
(1 hour ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-09 22:36:18
(1 hour ago)
(caddyscan) Scanner path probe from 172.86.74.236 (US/United States/236.74.86.172.static.cloudzy.com ...
show more
(caddyscan) Scanner path probe from 172.86.74.236 (US/United States/236.74.86.172.static.cloudzy.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 172.86.74.236 - - [09/Sep/2026:22:12:45 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 404 218 172.86.74.236 - - [09/Sep/2026:22:14:30 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.236 - - [09/Sep/2026:22:24:25 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.236 - - [09/Sep/2026:22:27:46 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 172.86.74.236 - - [09/Sep/2026:22:36:16 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-09-09 22:20:01
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-09 22:00:46
(1 hour ago)
Auto-ban: >3000 req/min op 2026-09-09
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-09 21:58:17
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:58:09.570273 2026] [security2:error] [pid 25113:tid 25113] [client 172.86.74.236:38140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johneiden.com"] [uri "/.git/config"] [unique_id "aqHWcWrJQtEq_1wSdRgn8QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
Esko
2026-09-09 21:32:12
(2 hours ago)
172.86.74.236 - - [09/Sep/2026:21:32:12 +0000] "GET /.git/config HTTP/1.1" 488 0 "-" "Mozilla/5.0 (X ...
show more
172.86.74.236 - - [09/Sep/2026:21:32:12 +0000] "GET /.git/config HTTP/1.1" 488 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-09 21:26:11
(2 hours ago)
[Thu Sep 10 07:26:10.479647 2026] [security2:error] [pid 430615] [client 172.86.74.236:43158] [clien ...
show more
[Thu Sep 10 07:26:10.479647 2026] [security2:error] [pid 430615] [client 172.86.74.236:43158] [client 172.86.74.236] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "aqHO8iKpoXdSSlUIaQFKWwAAAAE"], referer: https://vap.com.au/.git/config
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 21:24:50
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com ...
show more
(mod_security) mod_security (id:210492) triggered by 172.86.74.236 (236.74.86.172.static.cloudzy.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:24:44.812965 2026] [security2:error] [pid 26345:tid 26345] [client 172.86.74.236:60962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lambert-heating-and-air.com"] [uri "/.git/config"] [unique_id "aqHOnHqSyhfwUh-RBe3NmwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dom4k
2026-09-09 21:10:22
(2 hours ago)
172.86.74.236 - - [09/Sep/2026:21:10:21 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X ...
show more
172.86.74.236 - - [09/Sep/2026:21:10:21 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
Rip
2026-09-09 21:08:59
(2 hours ago)
Restricted File Access Attempts
Port Scan
Web App Attack
🇩🇪
Blexyel
2026-09-09 21:07:23
(2 hours ago)
172.86.74.236 - - [09/Sep/2026:23:07:23 +0200] "GET /.git/config HTTP/1.1" 401 179 "-" "Mozilla/5.0 ...
show more
172.86.74.236 - - [09/Sep/2026:23:07:23 +0200] "GET /.git/config HTTP/1.1" 401 179 "-" "Mozilla/5.0 (X11; Linux x86_64)" "disk-monitoring.pingusmc.org"
...
show less
Brute-Force
Web App Attack
🇪🇸
el-brujo
2026-09-09 21:04:22
(2 hours ago)
09/Sep/2026:23:04:22.183806 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
09/Sep/2026:23:04:22.183806 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 172.86.74.236] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "alpine.elhacker.net"] [uri "/.git/config"] [unique_id "aqHJ1rzDYrd7ZiKX6J5TgwAAFfc"]
...
show less
Hacking
Web App Attack