🇳🇱
ipoac.nl
2026-09-02 04:46:14
(3 days ago)
-:443 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [02/Sep/2026:06:46:12 +0200] - "GET /.git/config HTTP ...
show more
-:443 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [02/Sep/2026:06:46:12 +0200] - "GET /.git/config HTTP/1.1" 404 52677 "-" "Mozilla/5.0 (compatible; Konqueror/3.3; Linux 2.6.8-gentoo-r3; X11;"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-02 04:16:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:16:13.065608 2026] [security2:error] [pid 1042499:tid 1042542] [client 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f:44066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "30acre.com"] [uri "/.git/config"] [unique_id "apejDYxzIHI2Yu0WRxmMSwAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 02:05:06
(4 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇩🇪
Viveronese
2026-09-01 01:45:17
(4 days ago)
HTTP vulnerability scanning
Web App Attack
🇩🇪
Bedios GmbH
2026-09-01 01:33:47
(4 days ago)
Login credentials theft attempt
Hacking
🇩🇪
gadix
2026-09-01 01:22:18
(4 days ago)
[01/Sep/2026:01:52:17.388839 +0200] apYTsWhBkggcYzACaakNJAAAABQ 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f ...
show more
[01/Sep/2026:01:52:17.388839 +0200] apYTsWhBkggcYzACaakNJAAAABQ 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f 53866 127.0.0.1 7081
[01/Sep/2026:03:21:43.238351 +0200] apYop8KSC6QC-0w0i8CBpQAAAE8 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f 58528 127.0.0.1 7081
[01/Sep/2026:03:22:17.495664 +0200] apYoyWhBkggcYzACaakegQAAABE 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f 56268 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 01:21:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:21:46.005060 2026] [security2:error] [pid 12065:tid 12065] [client 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f:36886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.cocoscabanas.com"] [uri "/.git/config"] [unique_id "apYoquPLVRgcw2Bm9dx76QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
aranguren.org
2026-09-01 00:54:48
(4 days ago)
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [01/Sep/2026:10:34:09 +1000] "GET /.git/config HTTP/1.1" 20 ...
show more
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [01/Sep/2026:10:34:09 +1000] "GET /.git/config HTTP/1.1" 200 263 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 YaBrowser/19.7.2.470 Yowser/2.5 Safari/537.36"
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [01/Sep/2026:10:34:42 +1000] "GET /.git/config HTTP/1.1" 200 341 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36"
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [01/Sep/2026:10:54:47 +1000] "GET /.git/config HTTP/1.1" 301 281 "-" "Mozilla/5.0 (Linux; Android 8.1.0; SM-G390F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-01 00:11:32
(4 days ago)
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [31/Aug/2026:21:11:30 -0300] "GET /.git/config HTTP/1.1" 40 ...
show more
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [31/Aug/2026:21:11:30 -0300] "GET /.git/config HTTP/1.1" 403 180 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇳🇱
e.fierstra
2026-08-31 23:59:06
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-08-31 23:51:29
(4 days ago)
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [31/Aug/2026:17:51:29 -0600] "GET /.git/config HTTP/1.1" 30 ...
show more
2a05:d014:38:2e00:7b90:fa3e:a0b:c39f - - [31/Aug/2026:17:51:29 -0600] "GET /.git/config HTTP/1.1" 300 11409 "-" "Python-urllib/2.5"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 23:48:42
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:48:33.904694 2026] [security2:error] [pid 2018:tid 2039] [client 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f:41638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kuwaitcounseling.paygulf.com"] [uri "/.git/config"] [unique_id "apYS0VA_g6T7zsO8C3F-ugAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
kumiko
2026-08-31 23:41:25
(4 days ago)
[2026-09-01 02:41:24] Probing for dotfiles
"GET /.git/config HTTP/1.1" 403
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 22:47:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:46:57.156518 2026] [security2:error] [pid 26843:tid 26843] [client 2a05:d014:38:2e00:7b90:fa3e:a0b:c39f:44284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blue-attitude.net"] [uri "/.git/config"] [unique_id "apYEYR4jReC5PjTeC99M5AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-31 22:44:42
(4 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack