๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 08:05:04
(4 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 07:08:01
(5 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-22 06:58:46
(6 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: s3.dont-eat-the-pudding.top | URI: /.git/config | UA: Mozilla/5.0 (iPhone; CPU iPhone OS 18_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Mobile/15E148 Safari/604.1 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 06:39:53
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 02:39:49.783441 2026] [security2:error] [pid 23708:tid 23708] [client 34.128.125.22:35912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clinchspurs.com"] [uri "/.git/config"] [unique_id "arIitVELeiQecv3iTayo5wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 05:25:10
(7 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฌ๐ง
openstrike.co.uk
2026-09-22 05:14:30
(7 hours ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ฉ๐ช
kkw
2026-09-22 05:02:25
(7 hours ago)
[REDACTED] 34.128.125.22 - - [22/Sep/2026:07:02:24 +0200] "GET /.git/config HTTP/1.1" 404 4444 "-" " ...
show more
[REDACTED] 34.128.125.22 - - [22/Sep/2026:07:02:24 +0200] "GET /.git/config HTTP/1.1" 404 4444 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
its101
2026-09-22 04:50:08
(8 hours ago)
Automated detection by LockdownAccess security system. Attack type(s): git_exposure. Reason: Nginx: ...
show more
Automated detection by LockdownAccess security system. Attack type(s): git_exposure. Reason: Nginx: git_exposure attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 04:37:33
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 00:37:27.864866 2026] [security2:error] [pid 12066:tid 12066] [client 34.128.125.22:47098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "phillatwood.com"] [uri "/.git/config"] [unique_id "arIGByQoIyFVwRmzjklfpAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-22 02:37:13
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: status.budyn.ovh | URI: /.git/config | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-22 02:20:31
(10 hours ago)
[TueSep2204:20:26.4502862026][security2:error][pid2769620:tid2769707][client34.128.125.22:0]ModSecur ...
show more
[TueSep2204:20:26.4502862026][security2:error][pid2769620:tid2769707][client34.128.125.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"ristrutturazione-case.ch\"][uri\"/.git/config\"][unique_id\"arHl6tNAuUDDQ7_kPvt5LwAAAMY\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:07:55
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:07:51.116115 2026] [security2:error] [pid 25702:tid 25737] [client 34.128.125.22:33454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlinelawdegree.org.aafm.us"] [uri "/.git/config"] [unique_id "arHU52tZDWa1TqsgK4ErAwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 00:37:37
(12 hours ago)
319 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 00:11:30
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:11:23.964227 2026] [security2:error] [pid 16545:tid 16550] [client 34.128.125.22:41172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailporte.com"] [uri "/.git/config"] [unique_id "arHHq7YTw0gnlOp4fMongQAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:48:28
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.22 (22.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:48:21.949622 2026] [security2:error] [pid 1527:tid 1527] [client 34.128.125.22:52794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matomo.prolifeli.org"] [uri "/.git/config"] [unique_id "arHCRb4VhjG_OAfCSflicwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack