๐ง๐ช
cmbplf
2026-09-22 00:39:57
(19 minutes ago)
265 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-21 22:57:40
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.goblinpot.site | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:46:37
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:46:33.495281 2026] [security2:error] [pid 21683:tid 21683] [client 34.101.76.213:51668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casaroma-alassio.com"] [uri "/.git/config"] [unique_id "arGzyYuK2jKBgWtk4T8axwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:26:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:26:37.662436 2026] [security2:error] [pid 25429:tid 25429] [client 34.101.76.213:51878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waleed.co"] [uri "/.git/config"] [unique_id "arGvHQTq7zJMxn9q9x3V1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:10:59
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:10:56.563531 2026] [security2:error] [pid 27791:tid 27791] [client 34.101.76.213:45610] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solutiongroove.com"] [uri "/.git/config"] [unique_id "arGrcF03V2vudtIPBsZPJwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
xdearboy
2026-09-21 21:28:27
(3 hours ago)
Dionaea Honeypot: HTTP scan on path /.git/config
Hacking
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-21 20:54:06
(4 hours ago)
34.101.76.213 - - [21/Sep/2026:22:54:03 +0200] "GET /.git/config HTTP/1.1" 404 5141 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 20:39:53
(4 hours ago)
cloudlinux2 fail2ban: 2026-09-21 21:49:50,684 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 21:49:50,684 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.101.76.213 - 2026-09-21 21:49:50cloudlinux2 fail2ban: 2026-09-21 21:49:59,807 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.93.40.82 - 2026-09-21 21:49:59cloudlinux2 fail2ban: 2026-09-21 21:49:59,816 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.93.40.82 - 2026-09-21 21:49:59cloudlinux2 fail2ban: 2026-09-21 21:50:01,007 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 136.85.4.152 - 2026-09-21 21:50:01cloudlinux2 fail2ban: 2026-09-21 21:50:55,368 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 45.138.12.6 - 2026-09-21 21:50:55cloudlinux2 fail2ban: 2026-09-21 21:50:55,519 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 45.138.12.6 - 2026-09-21 21:50:55cloudlinux2 fail2ban: 2026-09-21 21:51:15,452 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 139.64.12.37 - 2026-09-21 21:51:15cloud
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 20:22:31
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:22:24.488810 2026] [security2:error] [pid 18682:tid 18682] [client 34.101.76.213:52902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stalbansparish.org"] [uri "/.git/config"] [unique_id "arGSADCx0vS9v5OEUPXN3gAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-21 19:58:40
(5 hours ago)
Try to access /.git/config
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-21 19:47:38
(5 hours ago)
[Tue Sep 22 05:47:37.892129 2026] [security2:error] [pid 155075] [client 34.101.76.213:41060] [clien ...
show more
[Tue Sep 22 05:47:37.892129 2026] [security2:error] [pid 155075] [client 34.101.76.213:41060] [client 34.101.76.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "stkildashule.org.au"] [uri "/.git/config"] [unique_id "arGJ2S-KIMmDVabJwlskNgAAAAo"]
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-21 19:25:01
(5 hours ago)
(y3) Failed access -byebye- from 34.101.76.213 (ID/Indonesia/213.76.101.34.bc.googleusercontent.com) ...
show more
(y3) Failed access -byebye- from 34.101.76.213 (ID/Indonesia/213.76.101.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฉ๐ช
YF
2026-09-21 19:20:19
(5 hours ago)
Git config exposure probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:52:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:52:04.174383 2026] [security2:error] [pid 23515:tid 23515] [client 34.101.76.213:52366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "multilize.com"] [uri "/.git/config"] [unique_id "arF81GmB9k6-zFlp0IgghQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:55:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.76.213 (213.76.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:55:31.450483 2026] [security2:error] [pid 20297:tid 20297] [client 34.101.76.213:54582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "strawusa.com"] [uri "/.git/config"] [unique_id "arFvk6lc7C8O9MmKAIV87gAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack