๐ฉ๐ช
IVski
2026-07-22 23:09:22
(45 minutes ago)
IVski WAF | Sensitive file probe detected - looking for .git
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:06:07
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:06:03.103083 2026] [security2:error] [pid 2168345:tid 2168345] [client 104.199.145.40:35800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atsgroup.llc.myllc.email"] [uri "/.git/config"] [unique_id "amFM27-OVNcco-HfocM8EgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 23:05:03
(50 minutes ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-07-22 23:03:03
(52 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-07-22 22:48:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-07-23 00:43:47,787 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-23 00:43:47,787 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.29 - 2026-07-23 00:43:47cloudlinux2 fail2ban: 2026-07-23 00:43:46,172 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.29 - 2026-07-23 00:43:46cloudlinux2 fail2ban: 2026-07-23 00:43:47,952 fail2ban.filter [1589]: INFO [recidive] Found 167.82.167.29 - 2026-07-23 00:43:47cloudlinux2 fail2ban: 2026-07-23 00:43:47,946 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 167.82.167.29cloudlinux2 fail2ban: 2026-07-23 00:43:45,997 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 167.82.167.29 - 2026-07-23 00:43:45cloudlinux2 fail2ban: 2026-07-23 00:44:37,615 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 194.61.40.158 - 2026-07-23 00:44:36cloudlinux2 fail2ban: 2026-07-23 00:44:48,170 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 104.199.145.40 - 2026-07-23 00:44:47cloudlinux2 fail2ban: 2026-07
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 22:47:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 18:47:44.887280 2026] [security2:error] [pid 1381395:tid 1381395] [client 104.199.145.40:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atlascoombs.com"] [uri "/.git/config"] [unique_id "amFIkG3Rc9vuUUj7AZFLKwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 22:19:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 18:19:18.384053 2026] [security2:error] [pid 1433479:tid 1433479] [client 104.199.145.40:41818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atelier92.com"] [uri "/.git/config"] [unique_id "amFB5tpeIAyyZE12SNMcvAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-22 21:59:14
(1 hour ago)
Auto-ban: >3000 req/min op 2026-07-22
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-22 21:50:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 17:50:46.392095 2026] [security2:error] [pid 2709972:tid 2709972] [client 104.199.145.40:49948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.astariamusic.com"] [uri "/.git/config"] [unique_id "amE7NkoPfpw90hmb498tigAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Selckie
2026-07-22 21:18:23
(2 hours ago)
fail2ban: NGINX unusual impact
Web App Attack
Anonymous
2026-07-22 21:16:11
(2 hours ago)
Trying to access config files
Web App Attack
๐ฑ๐น
NotACaptcha
2026-07-22 20:53:13
(3 hours ago)
webserver:443 [22/Jul/2026] "GET /.git/config HTTP/1.1" 302 5804
webserver:443 [22/Jul/2026] "GET ...
show more
webserver:443 [22/Jul/2026] "GET /.git/config HTTP/1.1" 302 5804
webserver:443 [22/Jul/2026] "GET /.git/config HTTP/1.1" 403 5691
show less
Web App Attack
Anonymous
2026-07-22 20:42:46
(3 hours ago)
104.199.145.40 - - [22/Jul/2026:20:42:45 +0000] "GET /.git/config HTTP/1.1" 404 34511 "-" "-"
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 20:39:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.145.40 (40.145.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:39:30.694003 2026] [security2:error] [pid 27288:tid 27294] [client 104.199.145.40:58740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asetiadi.net"] [uri "/.git/config"] [unique_id "amEqggnyFs79Mx_1_ZuyCAAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
micmor_asbl
2026-07-22 20:27:53
(3 hours ago)
ase-17 : Block hidden directories=>/.git/config(/)
Hacking