🇳🇱
oisecnet
2026-09-06 21:03:07
(3 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-06. 6629 requests from thi ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-06. 6629 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇫🇷
LRNP
2026-09-06 08:34:26
(4 days ago)
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /app/.git/config HTTP/1.1" 404 146 "-" "c ...
show more
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /app/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /backend/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /src/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /api/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /www/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /html/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/2026:08:34:26 +0000] "GET /public/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
_:8443 8.229.106.252 - - [06/Sep/202
...
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 04:32:40
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:34:39
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:34:34.100010 2026] [security2:error] [pid 26082:tid 26082] [client 8.229.106.252:33594] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unilabkenya.com"] [uri "/htdocs/.git/config"] [unique_id "apzfSnZEvowXxIltyT2jVAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-06 00:02:40
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇳🇱
e.fierstra
2026-09-05 23:23:57
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-05 23:05:36
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 8.229.106.252 (US/United States/252.106 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 8.229.106.252 (US/United States/252.106.229.8.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-05 22:34:05
(4 days ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:38:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:38:12.629881 2026] [security2:error] [pid 15628:tid 15628] [client 8.229.106.252:42004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "powersystemprotection.co.uk"] [uri "/.git/config"] [unique_id "apyLxG11zwz3ltq3hZ7ecQAAAHE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-05 11:20:33
(5 days ago)
8.229.106.252 - - [05/Sep/2026:06:20:33 -0500] "GET /html/.git/config HTTP/1.1" 404 162 "-" "crusade ...
show more
8.229.106.252 - - [05/Sep/2026:06:20:33 -0500] "GET /html/.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
8.229.106.252 - - [05/Sep/2026:06:20:33 -0500] "GET /public/.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
8.229.106.252 - - [05/Sep/2026:06:20:33 -0500] "GET /site/.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇩🇪
LRob
2026-09-05 07:43:11
(5 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wordpress/.git/config (+11 more) | 2026-09-05 07:43 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-04 23:07:07
(5 days ago)
Automated web scanner. Requested suspicious paths: /app/.git/config. UTC: 2026-09-04 23:02:00.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:46:48
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:46:42.593330 2026] [security2:error] [pid 23935:tid 23935] [client 8.229.106.252:53448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mbehel.com"] [uri "/.git/config"] [unique_id "aps8Qm8OX7CTlKSqwEm2FAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:31:20
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:06:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.106.252 (252.106.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:06:12.989489 2026] [security2:error] [pid 6704:tid 6704] [client 8.229.106.252:37998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rebeccapratt.com"] [uri "/var/www/.git/config"] [unique_id "apsyxJaoch7wxj0vZNoeVAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack