🇺🇸
TPI-Abuse
2026-09-02 18:00:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 14:00:49.168948 2026] [security2:error] [pid 9214:tid 9214] [client 136.115.84.255:57624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.xgoga.elpais.mx"] [uri "/.git/config"] [unique_id "aphkUR_NBDgNWX04zs0ElQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
LotPhantom
2026-09-02 17:39:19
(2 hours ago)
2026/09/02 17:39:19 [error] 1307128#1307128: *17765 access forbidden by rule, client: 136.115.84.255 ...
show more
2026/09/02 17:39:19 [error] 1307128#1307128: *17765 access forbidden by rule, client: 136.115.84.255, server: wynnesmiles.com, request: "GET /.git/config HTTP/1.1", host: "www.wynnesmiles.com"
...
show less
Web App Attack
🇺🇸
mnsf
2026-09-02 16:05:23
(3 hours ago)
Abuse Detected (14)
Brute-Force
Web App Attack
🇩🇪
big-cloud.nl
2026-09-02 15:24:42
(4 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 15:24:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:24:01.666024 2026] [security2:error] [pid 11028:tid 11028] [client 136.115.84.255:35472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wsspy.bamedica.com"] [uri "/.git/config"] [unique_id "apg_kSbK-wdNv9qO3GFXsAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 15:05:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:05:32.031792 2026] [security2:error] [pid 5769:tid 5769] [client 136.115.84.255:55682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wow-tx.com.srtmanagementservices.com"] [uri "/.git/config"] [unique_id "apg7PHpSNKwcyPvALourUQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-02 15:01:29
(4 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
🇩🇪
IVski.com
2026-09-02 14:54:57
(4 hours ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-02 14:51:49
(4 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 14:46:51
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 136.115.84.255 (255.84.115.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:46:44.666172 2026] [security2:error] [pid 19179:tid 19179] [client 136.115.84.255:38024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workequity.kporterdesign.com"] [uri "/.git/config"] [unique_id "apg21ONN8sf9r119GEi13AAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack