๐ฉ๐ช
XICTRON
2026-06-15 22:45:08
(2 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ง๐ท
Peregrine
2026-06-15 22:37:10
(2 hours ago)
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.25.136.57 - - [15/Jun/2026:19:37:07 -0300] "GET /.gi ...
show more
Fail2Ban Jail: tomcat-honeypot | Evidence: - 20.25.136.57 - - [15/Jun/2026:19:37:07 -0300] "GET /.git/config HTTP/1.1" 404 414
- 20.25.136.57 - - [15/Jun/2026:19:37:08 -0300] "GET /.git/config HTTP/1.1" 404 414
show less
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-06-15 22:35:20
(2 hours ago)
Try to access /.git/config
Web App Attack
Anonymous
2026-06-15 22:20:01
(3 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
LotPhantom
2026-06-15 22:06:08
(3 hours ago)
20.25.136.57 - - [15/Jun/2026:22:05:37 +0000] "GET /.git/config HTTP/1.1" 404 548 "-" "Mozilla/5.0 ( ...
show more
20.25.136.57 - - [15/Jun/2026:22:05:37 +0000] "GET /.git/config HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36" "0"
...
show less
Web App Attack
Anonymous
2026-06-15 21:55:03
(3 hours ago)
20.25.136.57 - - [15/Jun/2026:21:55:03 +0000] "GET /.git/config HTTP/1.1" 404 7030 "-" "Mozilla/5.0 ...
show more
20.25.136.57 - - [15/Jun/2026:21:55:03 +0000] "GET /.git/config HTTP/1.1" 404 7030 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-06-14 05:14:00
(1 day ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐บ๐ธ
markawes
2026-06-13 16:47:40
(2 days ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
20.25.136.57 - - [13/Jun/2026:17:33:00 +0100] "GET /.git/config HTTP/1.1" 404 492 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
20.25.136.57 - - [13/Jun/2026:17:33:00 +0100] "GET /.git/config HTTP/1.1" 404 3122 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
20.25.136.57 - - [13/Jun/2026:17:47:38 +0100] "GET /.git/config HTTP/1.1" 404 492 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
show less
Port Scan
Hacking
Web App Attack
๐ฉ๐ช
psauxit
2026-06-13 15:55:07
(2 days ago)
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrp ...
show more
Fail2Ban - NGINX bad requests 400-401-403-404-444, high level vulnerability scanning, commonly xmlrpc_attack, wp-login brute force, excessive crawling/scraping
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 15:36:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.25.136.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.25.136.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 11:35:58.596138 2026] [security2:error] [pid 32057:tid 32057] [client 20.25.136.57:38350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.99"] [uri "/.git/config"] [unique_id "ai143kqijTG_ltgBbupG3gAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 15:33:42
(2 days ago)
DNS Compromise
DDoS Attack
๐ซ๐ท
Thaliruth
2026-06-13 15:24:09
(2 days ago)
[13/Jun/2026:17:24:09.349599 +0200] ai12GbnC9vgkq0zTBmJxAAAAAFM 20.25.136.57 48306 127.0.0.1 7080
.. ...
show more
[13/Jun/2026:17:24:09.349599 +0200] ai12GbnC9vgkq0zTBmJxAAAAAFM 20.25.136.57 48306 127.0.0.1 7080
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-13 15:20:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 20.25.136.57 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 20.25.136.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 11:20:43.461425 2026] [security2:error] [pid 530:tid 541] [client 20.25.136.57:43012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/.git/config"] [unique_id "ai11S_-6-_7oD9v4ktan0AAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 22:00:44
(4 days ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
๐ฉ๐ช
barbarella
2026-06-11 14:04:08
(4 days ago)
Multiple (2) times attack on http port 80: Configuration snooping (GET /.git/config)
14:04:08 Co ...
show more
Multiple (2) times attack on http port 80: Configuration snooping (GET /.git/config)
14:04:08 Configuration snooping (GET /.git/config)
show less
Hacking
Web App Attack