🇳🇱
homeshowdomain.nl
2026-09-10 21:59:43
(2 hours ago)
Auto-ban: >3000 req/min op 2026-09-10
Web App Attack
SSH
Hacking
Anonymous
2026-09-10 13:45:11
(11 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.git/config
Bad Web Bot
Web App Attack
🇹🇷
oalver
2026-09-10 07:25:25
(17 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.git/config (HTTP 403). First seen: 2026-09-10. Risk score: 30/100.
show less
Web App Attack
Anonymous
2026-09-10 04:22:14
(20 hours ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
Mundo Bueno
2026-09-10 03:47:18
(21 hours ago)
[ISILIA Protection v2.1] Tentative d'accès: /.git/config | Pays: AU | UA: Mozilla/5.0 (X11; Linux x8 ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /.git/config | Pays: AU | UA: Mozilla/5.0 (X11; Linux x86_64)
show less
Hacking
Web App Attack
🇺🇸
abuse-opdc
2026-09-10 03:46:02
(21 hours ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-10 03:44:55
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 198.251.85.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 198.251.85.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:44:46.244802 2026] [security2:error] [pid 18927:tid 18927] [client 198.251.85.130:36522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "portalvasco.com"] [uri "/.git/config"] [unique_id "aqInrvuO0IcpdPsQa1SQ-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
pinguin
2026-09-10 03:40:36
(21 hours ago)
Triggered Cloudflare WAF (firewallManaged) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET meth ...
show more
Triggered Cloudflare WAF (firewallManaged) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (X11; Linux x86_64)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇬🇧
rakkor
2026-09-10 03:40:00
(21 hours ago)
2026/09/10 00:49:08 [error] 27538#27538: *5644916 open() "/usr/syno/synoman/.git/config" failed (2: ...
show more
2026/09/10 00:49:08 [error] 27538#27538: *5644916 open() "/usr/syno/synoman/.git/config" failed (2: No such file or directory), client: 198.251.85.130, server: audio.rakkor.uk, request: "GET /.git/config HTTP/1.1", host: "audio.rakkor.uk"
2026/09/10 04:39:59 [error] 24362#24362: *5652424 open() "/usr/syno/synoman/.git/config" failed (2: No such file or directory), client: 198.251.85.130, server: photo.rakkor.uk, request: "GET /.git/config HTTP/1.1", host: "photo.rakkor.uk"
...
show less
Brute-Force
Hacking
Web App Attack
🇵🇱
Budyn
2026-09-10 03:33:33
(21 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: panel.budyn.wtf | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇷
arsonist
2026-09-10 03:25:31
(21 hours ago)
[fail2ban]
2026-09-10T03:25:30.611942+00:00 arson caddy[1890453]: {"level":"info","ts":1789010730.61 ...
show more
[fail2ban]
2026-09-10T03:25:30.611942+00:00 arson caddy[1890453]: {"level":"info","ts":1789010730.611896,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"198.251.85.130","remote_port":"33818","client_ip":"198.251.85.130","proto":"HTTP/1.1","method":"GET","host":"ntfy.arson.gg","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64)"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"ntfy.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000102944,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇩🇪
dom4k
2026-09-10 03:23:05
(21 hours ago)
198.251.85.130 - - [10/Sep/2026:03:23:05 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 ( ...
show more
198.251.85.130 - - [10/Sep/2026:03:23:05 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 03:20:21
(21 hours ago)
PSCSERV WPSCAN 198.251.85.130
Bad Web Bot
Web App Attack
🇫🇷
GoodOldTOS
2026-09-10 03:17:31
(21 hours ago)
Bad keywords detected in request: /.git/config/.git
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-10 03:07:13
(21 hours ago)
Multiple WAF Violations
Web App Attack