Anonymous
2026-08-26 09:00:53
(23 hours ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
wbsouza
2026-08-26 03:31:47
(1 day ago)
CrowdSec: infra/bad-path-probe โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฌ๐ง
AvonleaConsulting
2026-08-25 17:20:12
(1 day ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-08-25 13:20:18
(1 day ago)
195.80.150.184 - - [25/Aug/2026:15:20:17 +0200] "GET /.git/config HTTP/1.1" 302 459 "-" "Go-http-cli ...
show more
195.80.150.184 - - [25/Aug/2026:15:20:17 +0200] "GET /.git/config HTTP/1.1" 302 459 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 13:11:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:11:44.822841 2026] [security2:error] [pid 3975:tid 3975] [client 195.80.150.184:39407] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hygeiamedical.icu"] [uri "/.git/config"] [unique_id "ao2UkHMtJzXOsW6JlttWiAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 12:57:46
(1 day ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐จ๐ญ
YF
2026-08-25 12:30:43
(1 day ago)
Git config exposure probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:18:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:17:58.211818 2026] [security2:error] [pid 3291:tid 3291] [client 195.80.150.184:42265] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightningbug.farm"] [uri "/.git/config"] [unique_id "ao2H9mLwgRKaf19ctC0RhQAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MarkGGN
2026-08-25 11:53:21
(1 day ago)
Web attack. 195.80.150.184 - - [25/Aug/2026:13:53:20 +0200] "GET /.git/config HTTP/1.1" 403 146 "htt ...
show more
Web attack. 195.80.150.184 - - [25/Aug/2026:13:53:20 +0200] "GET /.git/config HTTP/1.1" 403 146 "http://*/.git/config" "Go-http-client/1.1"
195.80.150.184 - - [25/Aug/2026:13:53:21 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "Go-http-client/1.1"
show less
Web App Attack
๐ฉ๐ช
raph
2026-08-25 11:41:16
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Admins@FBN
2026-08-25 11:15:33
(1 day ago)
FW-PortScan: Traffic Blocked srcport=61185 dstport=80
Port Scan
๐ฉ๐ช
london2038.com
2026-08-25 10:49:08
(1 day ago)
Probing for exploits
195.80.150.184 - - [25/Aug/2026:12:49:04 +0200] "GET /.git/config HTTP/1.1" 422 ...
show more
Probing for exploits
195.80.150.184 - - [25/Aug/2026:12:49:04 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
195.80.150.184 - - [25/Aug/2026:12:49:04 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Go-http-client/1.1"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:35:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:35:21.642011 2026] [security2:error] [pid 19811:tid 19811] [client 195.80.150.184:32333] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whodatnation.com"] [uri "/.git/config"] [unique_id "ao1v6Ury9e2vJcHyVaTQtwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:09:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:09:29.518982 2026] [security2:error] [pid 22120:tid 22120] [client 195.80.150.184:52759] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tedmccachren.com"] [uri "/.git/config"] [unique_id "ao1p2Z_QEtNmdHAwY5sLogAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:50:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 195.80.150.184 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:50:38.357018 2026] [security2:error] [pid 28735:tid 28735] [client 195.80.150.184:41621] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sheargrafix.com"] [uri "/.git/config"] [unique_id "ao1lbp3ITOmbBLjS0y_2ywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack