🇬🇧
andypiper
2026-09-10 01:00:47
(4 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇫🇷
arsonist
2026-09-10 00:56:50
(4 hours ago)
[fail2ban]
2026-09-10T00:56:49.277133+00:00 arson caddy[1890453]: {"level":"info","ts":1789001809.27 ...
show more
[fail2ban]
2026-09-10T00:56:49.277133+00:00 arson caddy[1890453]: {"level":"info","ts":1789001809.277103,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"2602:fa59:2:6d56::1","remote_port":"48216","client_ip":"2602:fa59:2:6d56::1","proto":"HTTP/1.1","method":"GET","host":"forum.furtress.tf","uri":"/.git/config","headers":{"User-Agent":["Mozilla/5.0 (X11; Linux x86_64)"],"Accept-Encoding":["gzip"],"Connection":["close"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"forum.furtress.tf","ech":false}},"bytes_read":0,"user_id":"","duration":0.000093877,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇺🇸
ambor
2026-09-10 00:15:37
(5 hours ago)
Honeypot access: Git configuration file access attempt. Path: /.git/config
Web App Attack
🇦🇹
René Hickersberger
2026-09-10 00:00:03
(5 hours ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (X11; Linux x86_64)"
Web App Attack
🇫🇷
Jimbo67
2026-09-09 23:55:48
(5 hours ago)
Cloudflare WAF: 1 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=0189 ...
show more
Cloudflare WAF: 1 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=0189a8c2c2ab4a60bc709bad14577d18 | URIs=/.git/config | confidence=0.82
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 23:55:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:55:13.453639 2026] [security2:error] [pid 20457:tid 20457] [client 2602:fa59:2:6d56::1:53198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ethicall.org"] [uri "/.git/config"] [unique_id "aqHx4b1wC2_jgxQBQS75HwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 23:36:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:36:53.752511 2026] [security2:error] [pid 31139:tid 31139] [client 2602:fa59:2:6d56::1:39502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hawksnestgolfcourse.smilingorc.com"] [uri "/.git/config"] [unique_id "aqHtlbqE1OdwFQkQlpCNUAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-09 23:19:35
(6 hours ago)
[redacted] 2602:fa59:2:6d56::1 - - [10/Sep/2026:00:19:32 +0100] "GET /.git/config HTTP/2.0" 301 295 ...
show more
[redacted] 2602:fa59:2:6d56::1 - - [10/Sep/2026:00:19:32 +0100] "GET /.git/config HTTP/2.0" 301 295 "https://[redacted]/.git/config" "Mozilla/5.0 (X11; Linux x86_64)" [redacted] 2602:fa59:2:6d56::1 - - [10/Sep/2026:00:19:33 +0100] "GET /fr/.git/config/ HTTP/2.0" 404 34684 "https://[redacted]/.git/config" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 23:15:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:15:22.861375 2026] [security2:error] [pid 30642:tid 30642] [client 2602:fa59:2:6d56::1:57984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grayowl.com"] [uri "/.git/config"] [unique_id "aqHoiihQyjpUSS41ArucVQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
000rosiu
2026-09-09 22:56:57
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 22:30:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 18:30:40.713152 2026] [security2:error] [pid 12349:tid 12349] [client 2602:fa59:2:6d56::1:47010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mta-sts.plugsinc.com"] [uri "/.git/config"] [unique_id "aqHeEKBZ3sPAScoWp-R0qQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
arsonist
2026-09-09 22:28:18
(6 hours ago)
[fail2ban]
2026-09-09T22:28:18.031014+00:00 arson caddy[1890453]: {"level":"info","ts":1788992898.03 ...
show more
[fail2ban]
2026-09-09T22:28:18.031014+00:00 arson caddy[1890453]: {"level":"info","ts":1788992898.0309823,"logger":"http.log.access.default","msg":"handled request","request":{"remote_ip":"2602:fa59:2:6d56::1","remote_port":"59294","client_ip":"2602:fa59:2:6d56::1","proto":"HTTP/1.1","method":"GET","host":"api.os.arson.gg","uri":"/.git/config","headers":{"Accept-Encoding":["gzip"],"Connection":["close"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64)"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"","server_name":"api.os.arson.gg","ech":false}},"bytes_read":0,"user_id":"","duration":0.000044364,"size":7,"status":418,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Content-Type":["text/plain; charset=utf-8"]}}
...
show less
Bad Web Bot
🇦🇺
Klaverstyn
2026-09-09 22:11:52
(7 hours ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
🇳🇱
JaRoNL
2026-09-09 21:33:55
(7 hours ago)
2602:fa59:2:6d56::1 - - [09/Sep/2026:23:33:54 +0200] "GET /.git/config HTTP/1.1" 404 7426 "-" "Mozil ...
show more
2602:fa59:2:6d56::1 - - [09/Sep/2026:23:33:54 +0200] "GET /.git/config HTTP/1.1" 404 7426 "-" "Mozilla/5.0 (X11; Linux x86_64)"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 21:02:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:2:6d56::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 17:02:41.537412 2026] [security2:error] [pid 26147:tid 26147] [client 2602:fa59:2:6d56::1:38638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinksite.net"] [uri "/.git/config"] [unique_id "aqHJceRTrVO5z9qCKuxdUwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack