π³π±
Alt255
2026-10-02 08:00:55
(1 hour ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 209.38.17.26 - - [02/Oct/2026:10:00:35 +0200] "GET /.git/config HTTP/1.1" 301 505 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/81.0.4044.129 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
paissangroup
2026-10-02 04:54:55
(4 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 03:25:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 23:25:07.710065 2026] [security2:error] [pid 13666:tid 13666] [client 209.38.17.26:36868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crowmoonmarketing.com"] [uri "/.git/config"] [unique_id "ar8kE8jUL_Pm_9dnoB4ndwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 02:24:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:24:44.264231 2026] [security2:error] [pid 32466:tid 32466] [client 209.38.17.26:40860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "scothart.com"] [uri "/.git/config"] [unique_id "ar8V7P0JQs_2yi-cZQvUPwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
ardoshipsquad
2026-10-02 01:04:58
(8 hours ago)
Web application attack (vulnerability scanning): 1 malicious requests within 30 minutes.
Bad Web Bot
Web App Attack
π©πͺ
sdos.es
2026-10-02 00:04:20
(9 hours ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"
Web App Attack
Anonymous
2026-10-02 00:04:03
(9 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
π³π΄
jad-abuse
2026-10-01 23:48:24
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-10-01 21:59:40
(11 hours ago)
Auto-ban: >3000 req/min op 2026-10-01
Web App Attack
SSH
Hacking
π©πͺ
altenglaner
2026-10-01 20:21:10
(13 hours ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 19:29:23
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 15:29:16.371593 2026] [security2:error] [pid 10376:tid 10376] [client 209.38.17.26:59866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phuket-day-trip.com"] [uri "/.git/config"] [unique_id "ar60jKyfCXo8UD115V6_SwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 17:05:56
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:05:50.935443 2026] [security2:error] [pid 31603:tid 31603] [client 209.38.17.26:42926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clossglobal.com"] [uri "/.git/config"] [unique_id "ar6S7nlk--ZVJl4LPTyIxgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 16:21:51
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:21:46.888249 2026] [security2:error] [pid 13472:tid 13472] [client 209.38.17.26:57976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "produktives.com"] [uri "/.git/config"] [unique_id "ar6ImtJcClqYHJQ6zT_4GQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-10-01 14:19:59
(19 hours ago)
Accessed trap at '/.git/config'
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:54:00
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 209.38.17.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:53:53.289135 2026] [security2:error] [pid 25980:tid 25980] [client 209.38.17.26:38494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pr-professional.com"] [uri "/.git/config"] [unique_id "ar5X4Q6Z0r6hRrLydaVvpAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack