๐ฉ๐ช
big-cloud.nl
2026-09-14 06:29:46
(4 days ago)
Try to access /.git/HEAD
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 06:04:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 02:04:49.695914 2026] [security2:error] [pid 1780:tid 1780] [client 2602:fa59:10:7fb::1:46760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accommodation-perthairport.com"] [uri "/.git/HEAD"] [unique_id "aqeOgek9lIcoyZujqy0CywAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-14 05:43:53
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 05:40:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:40:47.618486 2026] [security2:error] [pid 15403:tid 15413] [client 2602:fa59:10:7fb::1:39424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldcarz.com"] [uri "/.git/HEAD"] [unique_id "aqeI3wqULHpyyOf1w1fDhwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-14 05:33:54
(4 days ago)
201 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ซ๐ท
Baking333
2026-09-14 05:08:28
(4 days ago)
[redacted] 2602:fa59:10:7fb::1 - - [14/Sep/2026:06:08:26 +0100] "GET /.git/HEAD HTTP/1.1" 302 1538 0 ...
show more
[redacted] 2602:fa59:10:7fb::1 - - [14/Sep/2026:06:08:26 +0100] "GET /.git/HEAD HTTP/1.1" 302 1538 0/37800 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" [redacted] 2602:fa59:10:7fb::1 - - [14/Sep/2026:06:08:26 +0100] "GET / HTTP/1.1" 200 8407 0/99645 "https://[redacted]/.git/HEAD" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 05:08:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:08:19.886700 2026] [security2:error] [pid 5060:tid 5060] [client 2602:fa59:10:7fb::1:50724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "russiacoin.info"] [uri "/.git/HEAD"] [unique_id "aqeBQzSk0P54Hy_zbpuvLwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-14 04:46:27
(4 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/HEAD | 2026-09-14 04:46 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 04:45:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 00:44:58.468993 2026] [security2:error] [pid 14990:tid 15011] [client 2602:fa59:10:7fb::1:53410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kellenlee.com"] [uri "/.git/HEAD"] [unique_id "aqd7ylRtzng1XCAI-j6bwgAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-14 04:09:40
(4 days ago)
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 2602:fa59:10:7fb::1 - - [14/Sep/2026:06:09:39 +0200] "GET /.git/HEAD HTTP/1.1" 403 4565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-14 03:56:39
(4 days ago)
[MonSep1405:56:32.1950872026][security2:error][pid2991361:tid2991388][client2602:fa59:10:7fb::1:0]Mo ...
show more
[MonSep1405:56:32.1950872026][security2:error][pid2991361:tid2991388][client2602:fa59:10:7fb::1:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hosting-e-domini.com\"][uri\"/.git/HEAD\"][unique_id\"aqdwcBazPa85AhqZf9p2PQAAAUw\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 03:42:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 23:41:57.481517 2026] [security2:error] [pid 1365:tid 1365] [client 2602:fa59:10:7fb::1:41276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laboquimia.es"] [uri "/.git/HEAD"] [unique_id "aqdtBYtgtd3Ljit65PWhsAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 02:52:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:10:7fb::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 22:52:50.144138 2026] [security2:error] [pid 23850:tid 23864] [client 2602:fa59:10:7fb::1:48736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cheqs.org"] [uri "/.git/HEAD"] [unique_id "aqdhglz1r5aqm0HpXnGHSQAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack