๐บ๐ธ
TPI-Abuse
2026-09-22 09:29:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:29:18.622814 2026] [security2:error] [pid 13720:tid 13850] [client 34.101.98.177:54250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aussiepens.com"] [uri "/.git/config"] [unique_id "arJKbirMyVdROKIIOGKhsAAAAos"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:52:09
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:52:04.715044 2026] [security2:error] [pid 22990:tid 22990] [client 34.101.98.177:46250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "curtchristian.us"] [uri "/.git/config"] [unique_id "arIzpG19i4cVgb5H-IbKFQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 07:26:32
(4 hours ago)
[cb-03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-03al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.101.98.177 - - [22/Sep/2026:09:26:22 +0200] "GET /.git/config HTTP/1.1" 301 5825 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:15:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:14:57.046211 2026] [security2:error] [pid 21907:tid 21907] [client 34.101.98.177:55996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sunjammer.org"] [uri "/.git/config"] [unique_id "arIq8cdFQbKpn76-S-QXKAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-22 06:39:25
(5 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.astropot.website | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_2) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.1 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-09-22 06:34:59
(5 hours ago)
Probing for exploits
34.101.98.177 - - [22/Sep/2026:08:34:56 +0200] "GET /.git/config HTTP/1.1" 422 ...
show more
Probing for exploits
34.101.98.177 - - [22/Sep/2026:08:34:56 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/130.0.0.0 Safari/537.36 Edg/130.0.0.0"
34.101.98.177 - - [22/Sep/2026:08:34:55 +0200] "GET /.git/config HTTP/1.1" 422 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ฉ๐ช
sternwart
2026-09-22 06:25:27
(5 hours ago)
Automatisch erkannt: Zugriff auf /.git/config (xn--waschbr-alarm-gfb.ch)
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-22 06:19:58
(5 hours ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.101.98.177 - - \[22/Sep/2026:08:19:40 +0200\] "GET /.git/config HTTP/1.1" 301 5991 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-22 05:37:19
(6 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ฎ๐น
Inartis
2026-09-22 05:23:50
(6 hours ago)
34.101.98.177 - - [22/Sep/2026:07:23:49 +0200] "GET /.git/config HTTP/1.1" 403 5007 "-" "Mozilla/5.0 ...
show more
34.101.98.177 - - [22/Sep/2026:07:23:49 +0200] "GET /.git/config HTTP/1.1" 403 5007 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-22 05:03:33
(6 hours ago)
[TueSep2207:03:29.3990792026][security2:error][pid2940765:tid2941101][client34.101.98.177:0]ModSecur ...
show more
[TueSep2207:03:29.3990792026][security2:error][pid2940765:tid2941101][client34.101.98.177:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"xn--walter-wrndli-pmb.ch\"][uri\"/.git/config\"][unique_id\"arIMIRlUbu_l8A4Q1K-sdwAAANA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:27:55
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:27:48.172254 2026] [security2:error] [pid 4967:tid 4967] [client 34.101.98.177:60170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railsolutions.mx"] [uri "/.git/config"] [unique_id "arHnpGAo1uRC7BFpHpHuwAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-22 02:22:50
(9 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.teddypot.pro | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:57:24
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.98.177 (177.98.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:57:20.126458 2026] [security2:error] [pid 16037:tid 16037] [client 34.101.98.177:42652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dogarttoday.com"] [uri "/.git/config"] [unique_id "arHggMaRO5s8dZioj4nHSAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 01:32:46
(10 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config | 2026-09-22 01:32 UTC
show less
Hacking
Web App Attack