๐น๐ท
oalver
2026-09-27 08:59:42
(2 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /.git/config (HTTP 301). First seen: 2026-09-27. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 05:12:11
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; ...
show more
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 01:12:05.027553 2026] [security2:error] [pid 26236:tid 26266] [client 217.156.64.164:58724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.123"] [uri "/.git/config"] [unique_id "arilpcRepeKPxDkRrlldCwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-27 04:54:19
(6 hours ago)
tcp/80 (2 or more attempts)
Port Scan
๐ฉ๐ช
0x44
2026-09-27 04:51:12
(6 hours ago)
Abusive host detected - Web probing for vulnerabilities
Web App Attack
Hacking
๐ง๐ท
Host One
2026-09-27 04:10:03
(7 hours ago)
T-Pot Honeypot alert: 19 malicious events (exploit_attempt, port_scan) detected.
Port Scan
Hacking
Anonymous
2026-09-27 04:04:41
(7 hours ago)
Web Server Exposed Git Repository Information Disclosure.
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-27 03:28:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; ...
show more
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 23:28:19.957199 2026] [security2:error] [pid 11951:tid 11951] [client 217.156.64.164:56834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.153"] [uri "/.git/config"] [unique_id "ariNUz2u00-Tf9Xj693ipQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 02:40:58
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; ...
show more
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 22:40:53.942662 2026] [security2:error] [pid 11636:tid 11636] [client 217.156.64.164:44822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.151.11"] [uri "/.git/config"] [unique_id "ariCNZZE56cHtwkAvg9KcwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 00:41:32
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; ...
show more
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:41:27.971061 2026] [security2:error] [pid 21611:tid 21611] [client 217.156.64.164:34940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.229"] [uri "/.git/config"] [unique_id "arhmN7ZF_t72A2X33k-HFgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
donarev419
2026-09-27 00:00:16
(11 hours ago)
Port scan detected on port 80 (connection without data transfer)
Port Scan
๐บ๐ธ
brantknudson.org
2026-09-26 23:53:40
(11 hours ago)
Request path 'GET /.git/config HTTP/1.1'
Web App Attack
Hacking
๐ฆ๐น
vikal
2026-09-26 23:36:05
(11 hours ago)
217.156.64.164 - - [27/Sep/2026:01:36:04 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "EIMS/1.0"
. ...
show more
217.156.64.164 - - [27/Sep/2026:01:36:04 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "EIMS/1.0"
...
show less
Brute-Force
SSH
๐ฉ๐ช
tsZero
2026-09-26 22:56:56
(12 hours ago)
Scan example: path=/.git/config status=404
Hacking
๐ฆ๐บ
Bay13
2026-09-26 21:30:37
(14 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 19:47:22
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; ...
show more
(mod_security) mod_security (id:210492) triggered by 217.156.64.164 (hello): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 15:47:18.524070 2026] [security2:error] [pid 4042:tid 4042] [client 217.156.64.164:49082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.167"] [uri "/.git/config"] [unique_id "arghRu08rczBV0Xm2aympgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack