πΊπΈ
Epimetheus
2026-07-31 22:30:22
(4 minutes ago)
Unauthorized access attempts:
[GET] /.git/config
UA: Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:1 ...
show more
Unauthorized access attempts:
[GET] /.git/config
UA: Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:109.0) Gecko/20100101 Firefox/112.0
show less
Web App Attack
π©πͺ
yitzhaq
2026-07-31 22:28:29
(5 minutes ago)
3.75.224.22 - - [01/Aug/2026:00:28:25 +0200] "GET /.git/config HTTP/1.1" 403 467 "-" "Mozilla/5.0 (W ...
show more
3.75.224.22 - - [01/Aug/2026:00:28:25 +0200] "GET /.git/config HTTP/1.1" 403 467 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; WOW64; rv:41.0) Gecko/20100101 Firefox/140.0.2 (x64 de)"
3.75.224.22 - - [01/Aug/2026:00:26:47 +0200] "GET /.git/config HTTP/1.1" 403 4467 "-" "Mozilla/5.0 (Debian; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36"
3.75.224.22 - - [01/Aug/2026:00:28:27 +0200] "GET /.git/config HTTP/1.1" 403 4457 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36"
show less
Web App Attack
Hacking
πΊπΈ
Starburst SysOp Team
2026-07-31 22:27:10
(7 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
π¬π§
SilverZippo
2026-07-31 22:26:32
(7 minutes ago)
Web App Attack
Web App Attack
πΊπΈ
Major Hostility
2026-07-31 22:26:26
(7 minutes ago)
"GET /.git/config HTTP/1.1" 404
"GET /.git/config HTTP/1.1" 404
Web App Attack
π³π±
javierin
2026-07-31 22:22:43
(11 minutes ago)
3.75.224.22 - mazda.javierin.com - - [31/Jul/2026:22:19:18 +0000] "GET /.git/config HTTP/1.1" 404 23 ...
show more
3.75.224.22 - mazda.javierin.com - - [31/Jul/2026:22:19:18 +0000] "GET /.git/config HTTP/1.1" 404 2312 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.127 Safari/537.36"
3.75.224.22 - monitor.javierin.com - - [31/Jul/2026:22:22:42 +0000] "GET /.git/config HTTP/1.1" 404 2312 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/125.0"
...
show less
Web App Attack
Hacking
π¬π§
seniorlinuxadmin
2026-07-31 22:21:13
(13 minutes ago)
3.75.224.22 - - [31/Jul/2026:23:21:11 +0100] "GET /.git/config HTTP/1.1" 404 158 "-" "Mozilla/5.0 (Z ...
show more
3.75.224.22 - - [31/Jul/2026:23:21:11 +0100] "GET /.git/config HTTP/1.1" 404 158 "-" "Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
Web App Attack
π©πͺ
ut-addicted.com
2026-07-31 22:10:59
(23 minutes ago)
\[Sat Aug 01 00:10:57.825301 2026\] \[:error\] \[pid 31907:tid 139785800742656\] \[client 3.75.224.2 ...
show more
\[Sat Aug 01 00:10:57.825301 2026\] \[:error\] \[pid 31907:tid 139785800742656\] \[client 3.75.224.22:47624\] \[client 3.75.224.22\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "mail.ut-addicted.com"\] \[uri "/.git/config"\] \[unique_id "am0dcR-khWo4yQ1IL3ogiQAAAQo"\]
show less
Brute-Force
Web App Attack
πΊπΈ
JustMeHere
2026-07-31 22:10:12
(24 minutes ago)
[Fri Jul 31 18:10:03.548728 2026] [security2:error] [pid 911:tid 1045] [client 3.75.224.22:59090] Mo ...
show more
[Fri Jul 31 18:10:03.548728 2026] [security2:error] [pid 911:tid 1045] [client 3.75.224.22:59090] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mail.yorknation.com"] [uri "/.git/config"] [unique_id "am0dO3abvtcP03N2bBgPAgAAAIo"]
...
show less
Web App Attack
π©πͺ
Holger
2026-07-31 22:09:44
(24 minutes ago)
URL probing: GET /.git/config
Web App Attack
π¬π§
WebNiraj
2026-07-31 22:09:21
(25 minutes ago)
(mod_security) mod_security (id:949110) triggered by 3.75.224.22 (DE/Germany/ec2-3-75-224-22.eu-cent ...
show more
(mod_security) mod_security (id:949110) triggered by 3.75.224.22 (DE/Germany/ec2-3-75-224-22.eu-central-1.compute.amazonaws.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
Anonymous
2026-07-31 22:09:07
(25 minutes ago)
Http Port:80 (http_status:403) - Agent:Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, lik ...
show more
Http Port:80 (http_status:403) - Agent:Mozilla/5.0 (ZZ; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
show less
Web App Attack
Anonymous
2026-07-31 22:05:13
(29 minutes ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
πΊπΈ
chronos
2026-07-31 22:05:05
(29 minutes ago)
[AUTORAVALT][[31/07/2026 - 19:05:05 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.75.224.22] ...
show more
[AUTORAVALT][[31/07/2026 - 19:05:05 -03:00 UTC]
Attack from [Amazon Technologies Inc.]
[3.75.224.22][ec2-3-75-224-22.eu-central-1.compute.amazonaws.com]
Action: BLocKed
Hacking... Unauthorized attempts to access the server.
Web App Attack -> Attempts to probe for or exploit installed web applications such as a CMS like WordPress/Drupal, e-commerce solutions, ]
...
show less
Hacking
Web App Attack
π΅π±
srebrakowski.com
2026-07-31 22:02:48
(31 minutes ago)
crowdsec/waf-detected-exploits
Brute-Force