π―π΅
Valhalla
2026-09-01 11:14:18
(3 hours ago)
/.git/config
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 00:50:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:49:57.306345 2026] [security2:error] [pid 23013:tid 23013] [client 104.199.251.232:53634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wallawallafirearmstraining.com"] [uri "/.git/config"] [unique_id "apYhNXo8xk_zRs3jp1dDtgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-09-01 00:35:15
(14 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
π³π±
BlueWire Hosting
2026-09-01 00:27:47
(14 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-08-31 20:23:32
(18 hours ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 19:06:36
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 15:06:30.054875 2026] [security2:error] [pid 21016:tid 21016] [client 104.199.251.232:13828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiteblackbird.com"] [uri "/.git/config"] [unique_id "apXQtpNeGub8OA5sdlzRjgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 17:48:40
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 13:48:33.145362 2026] [security2:error] [pid 13885:tid 13885] [client 104.199.251.232:47006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tobyscott.com"] [uri "/.git/config"] [unique_id "apW-cTnMmtuVLu42miVfDQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 16:14:43
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 12:14:36.588791 2026] [security2:error] [pid 28594:tid 28597] [client 104.199.251.232:2642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "skillscredentials.com"] [uri "/.git/config"] [unique_id "apWobJxF6chstAm3f-SQVAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-08-31 16:14:36
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
sandra361
2026-08-31 16:00:02
(22 hours ago)
Cloudflare WAF: 1 request from AS396982/TW | Action: block | GET HTTP/1.1 | Paths: /.git/config | Us ...
show more
Cloudflare WAF: 1 request from AS396982/TW | Action: block | GET HTTP/1.1 | Paths: /.git/config | User Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Web App Attack
π«π·
Apotheas
2026-08-31 14:42:40
(1 day ago)
Honeypot trigger: GET /.git/config β {}
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 13:58:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 09:58:06.903503 2026] [security2:error] [pid 15155:tid 15155] [client 104.199.251.232:11506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "norkyn.com"] [uri "/.git/config"] [unique_id "apWIbm5XlXEqP3XECwaz4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 11:25:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:25:51.781110 2026] [security2:error] [pid 16543:tid 16543] [client 104.199.251.232:37058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ufcmusic.com"] [uri "/.git/config"] [unique_id "apVkvxRYBphxjKG2HMuYngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 08:46:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:46:33.382876 2026] [security2:error] [pid 8577:tid 8577] [client 104.199.251.232:62334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sedemo.xyz"] [uri "/.git/config"] [unique_id "apU_aestbp8ta4yq7LoWhAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 03:42:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.251.232 (232.251.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:42:50.051349 2026] [security2:error] [pid 6700:tid 6700] [client 104.199.251.232:42768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harmonyfactor.com"] [uri "/.git/config"] [unique_id "apT4OqMhMIrU_NO7rfD4KwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack