193.32.162.157
Case file
First seen on 2026-10-03T06:41:56Z, most recently active on 2026-10-05T17:58:17Z.
Recorded 16 attack-shaped requests across 3 separate days.
Its traffic probed for an exposed .git directory to download the site's source history and config; it also requested the .git directory itself, hoping it is exposed and browsable; it also probed for an exposed .svn directory to read the site's version-control metadata.
Seen on our web sensor.
Scored into the "Brute" level, carrying the badge Regular.
Routed via AS47890 (Unmanaged Ltd), an ASN we classify as residential.
Blocked by the firewalls on our servers since 2026-10-05T16:10:04Z, through 2026-11-04T16:10:04Z.
Enrichment
| rDNS | none |
|---|---|
| ASN | AS47890 — Unmanaged Ltd |
| ASN type | residential |
| Country | Romania (RO) |
| Flags | none observed |
Timeline
- 2026-10-034
- 2026-10-044
- 2026-10-058
Evidence (newest first, up to 50)
| Time (UTC) | Vantage | Site | Class | Status | Evidence |
|---|---|---|---|---|---|
| 2026-10-05T17:58:17Z | web | homocontinum.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | /.svn -> 403 |
| 2026-10-05T17:58:17Z | web | homocontinum.com | probed for an exposed .svn directory to read the site's version-control metadata | 403 | GET /.svn/wc.db -> 403 |
| 2026-10-05T15:57:00Z | web | homocontinum.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T15:57:00Z | web | homocontinum.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-05T15:56:56Z | web | 2 sites | 2 × requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-05T15:56:56Z | web | 2 sites | 2 × probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-04T01:25:37Z | web | 2 sites | 2 × requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-04T01:25:37Z | web | 2 sites | 2 × probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-03T15:48:18Z | web | motoristi.eu | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-03T10:28:17Z | web | carrentvarna.com | requested the .git directory itself, hoping it is exposed and browsable | 403 | /.git -> 403 |
| 2026-10-03T10:28:17Z | web | carrentvarna.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
| 2026-10-03T06:41:56Z | web | odor-ex.com | made a request that matched no known pattern | 403 | /odor-ex.com/.git -> 403 |
| 2026-10-03T06:41:56Z | web | odor-ex.com | probed for an exposed .git directory to download the site's source history and config | 403 | GET /.git/config -> 403 |
Not currently correlated with any campaign.
Dispute or removal: [email protected] — reference 193.32.162.157. See /threats/about for the method and the 7-day review window.
card.svg (used as this page's og:image)