๐บ๐ธ
Starburst SysOp Team
2026-10-05 15:52:06
(1 minute ago)
. Matched phrase "/.git/" at REQUEST_URI. (210492-srv1)
Web App Attack
๐ฉ๐ช
IVski.com
2026-10-05 15:49:42
(4 minutes ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-10-05 15:49:42
(4 minutes ago)
external host: 216.81.248.2 - - [05/Oct/2026:17:49:41 +0200] "GET /.git/config HTTP/1.1" 403 6139 "- ...
show more
external host: 216.81.248.2 - - [05/Oct/2026:17:49:41 +0200] "GET /.git/config HTTP/1.1" 403 6139 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36" CF-Ray:- CF-IP:-
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 15:36:52
(17 minutes ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 216 ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 216.81.248.2 - - \[05/Oct/2026:17:36:40 +0200\] "GET /.git/config HTTP/1.1" 301 6476 "-" "Mozilla/5.0 \(SMART-TV\; X11\; Linux armv7l\) AppleWebkit/537.42 \(KHTML, like Gecko\) Chromium/25.0.1349.2 Chrome/25.0.1349.2 Safari/537.42"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-05 15:34:34
(19 minutes ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐จ๐ญ
GAS
2026-10-05 15:31:29
(22 minutes ago)
Bad Bot.
216.81.248.2 - - [05/Oct/2026:17:31:29 +0200] "GET /.git/config HTTP/1.1" 301 1110 "-" "Moz ...
show more
Bad Bot.
216.81.248.2 - - [05/Oct/2026:17:31:29 +0200] "GET /.git/config HTTP/1.1" 301 1110 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X 10.5; en-US; rv:1.9.2.15) Gecko/20110303 Firefox/3.6.15"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
arsonist
2026-10-05 15:29:20
(24 minutes ago)
[fail2ban]
2026-10-05T15:29:20.302808+00:00 arson caddy[1712]: {"level":"info","ts":1791214160.30277 ...
show more
[fail2ban]
2026-10-05T15:29:20.302808+00:00 arson caddy[1712]: {"level":"info","ts":1791214160.3027704,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"216.81.248.2","remote_port":"38826","client_ip":"216.81.248.2","proto":"HTTP/1.1","method":"GET","host":"vw.arson.gg","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (X11; U; Linux i686; en-US; rv:1.9.0.11) Gecko/2009060309 Ubuntu/9.10 (karmic) Firefox/3.0.11"],"Accept-Charset":["utf-8"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"vw.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000093136,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
๐ณ๐ฑ
Tsumugi Kotobuki
2026-10-05 15:27:42
(26 minutes ago)
Web Scan (L7) | Paths: /.git/config | Codes: 444(1x) | rDNS: bratton.brattonsteel.com | F2B/angie-pa ...
show more
Web Scan (L7) | Paths: /.git/config | Codes: 444(1x) | rDNS: bratton.brattonsteel.com | F2B/angie-path-trap@2026-10-05T15:27:42Z
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-05 15:24:37
(29 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: minio.astropot.store | URI: /.git/config | UA: Mozilla/5.0 (X11; FreeBSD i386; rv:28.0) Gecko/20100101 Firefox/28.0 SeaMonkey/2.25 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 15:21:54
(32 minutes ago)
(caddyscan) Scanner path probe from 216.81.248.2 (US/United States/bratton.brattonsteel.com): 5 in t ...
show more
(caddyscan) Scanner path probe from 216.81.248.2 (US/United States/bratton.brattonsteel.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 216.81.248.2 - - [05/Oct/2026:15:02:30 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 216.81.248.2 - - [05/Oct/2026:15:04:08 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 216.81.248.2 - - [05/Oct/2026:15:07:30 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 216.81.248.2 - - [05/Oct/2026:15:20:40 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 216.81.248.2 - - [05/Oct/2026:15:21:49 +0000] "GET /.git/config HTTP/1.1"
show less
Port Scan
Anonymous
2026-10-05 15:09:25
(44 minutes ago)
216.81.248.2 - - [05/Oct/2026:23:09:24 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ( ...
show more
216.81.248.2 - - [05/Oct/2026:23:09:24 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/535.1 (KHTML, like Gecko) Chrome/13.0.782.20 Safari/535.1"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-10-05 15:08:14
(45 minutes ago)
Blocked by ConnMonitor
Web App Attack
๐ฉ๐ช
altenglaner
2026-10-05 15:05:44
(48 minutes ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-10-05 15:05:37
(48 minutes ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐บ๐ธ
Thermogenic
2026-10-05 15:02:30
(51 minutes ago)
Fail2Ban nginx-scanners: automated vulnerability scanning detected
Web App Attack