🇳🇱
homeshowdomain.nl
2026-09-08 22:00:00
(1 hour ago)
Auto-ban: >3000 req/min op 2026-09-08
Web App Attack
SSH
Hacking
🇩🇪
LRob
2026-09-08 20:21:27
(2 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/HEAD | 2026-09-08 20:21 U ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/HEAD | 2026-09-08 20:21 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:17:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225. ...
show more
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225.ft.lns.abo.bbox.fr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:17:43.197564 2026] [security2:error] [pid 2089:tid 2089] [client 212.195.255.225:5460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcmillerjr.com"] [uri "/.git/HEAD"] [unique_id "aqBtZ270h0TxVhgILpxi9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Major Hostility
2026-09-08 20:09:40
(3 hours ago)
"GET /.git/HEAD HTTP/1.1" 404
"GET /.git/config HTTP/1.1" 404
Web App Attack
🇫🇷
Baking333
2026-09-08 19:46:45
(3 hours ago)
[redacted] 212.195.255.225 - - [08/Sep/2026:20:46:43 +0100] "GET /.git/HEAD HTTP/1.1" 302 6763 0/420 ...
show more
[redacted] 212.195.255.225 - - [08/Sep/2026:20:46:43 +0100] "GET /.git/HEAD HTTP/1.1" 302 6763 0/42055 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" [redacted] 212.195.255.225 - - [08/Sep/2026:20:46:43 +0100] "GET /.git/config HTTP/1.1" 302 1544 0/38397 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:44:18
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225. ...
show more
(mod_security) mod_security (id:949110) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225.ft.lns.abo.bbox.fr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:44:10.391680 2026] [security2:error] [pid 24364:tid 24364] [client 212.195.255.225:5555] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "alexcorp.click"] [uri "/.git/HEAD"] [unique_id "aqBlioubaNern1b1c89y3gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 18:30:39
(4 hours ago)
417 requests with url.path */.git/config
299 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇫🇷
UnixPrime
2026-09-08 18:19:23
(4 hours ago)
212.195.255.225 - - [08/Sep/2026:20:19:21 +0200] "GET /.git/HEAD HTTP/1.1" 404 13953 "-" "Mozilla/5. ...
show more
212.195.255.225 - - [08/Sep/2026:20:19:21 +0200] "GET /.git/HEAD HTTP/1.1" 404 13953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
212.195.255.225 - - [08/Sep/2026:20:19:22 +0200] "GET /.git/config HTTP/1.1" 404 13955 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:01:06
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225. ...
show more
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225.ft.lns.abo.bbox.fr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:01:01.372143 2026] [security2:error] [pid 29300:tid 29300] [client 212.195.255.225:5592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asiancommoditiescorporation.com"] [uri "/.git/HEAD"] [unique_id "aqBNXfNvxFQ3zJGBl0riAQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:35:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225. ...
show more
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225.ft.lns.abo.bbox.fr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:35:36.894104 2026] [security2:error] [pid 7930:tid 7930] [client 212.195.255.225:5383] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adspirowellness.com"] [uri "/.git/HEAD"] [unique_id "aqBHaLXRK8eAI2ayF5mrhgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
arsonist
2026-09-08 17:03:47
(6 hours ago)
This IP accessed the path /.git/config, which is banned. Powered by ListenCaddy
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-08 17:01:13
(6 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.website | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:52:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225. ...
show more
(mod_security) mod_security (id:210492) triggered by 212.195.255.225 (i16-lef01-ix2-212-195-255-225.ft.lns.abo.bbox.fr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:52:33.935084 2026] [security2:error] [pid 1264:tid 1264] [client 212.195.255.225:5480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "addisonchiropracticcenter.com"] [uri "/.git/HEAD"] [unique_id "aqA9Ueg_zZPck7f9vTY4RAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:25:01
(6 hours ago)
suspicious request in access.log
Web App Attack
🇳🇴
jad-abuse
2026-09-08 16:23:39
(6 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 4 hits.
show less
Web App Attack