Anonymous
2026-09-04 13:54:04
(5 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /backend/.git/config HTTP/1.1 ...
show more
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1, GET /backend/.git/config HTTP/1.1, GET /html/.git/config HTTP/1.1
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-04 10:37:02
(8 hours ago)
300 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇺🇸
WPJoe
2026-09-04 08:10:42
(10 hours ago)
34.104.154.120 - - [04/Sep/2026:08:10:41 +0000] "GET /htdocs/.git/config HTTP/1.1" 301 501 "-" "crus ...
show more
34.104.154.120 - - [04/Sep/2026:08:10:41 +0000] "GET /htdocs/.git/config HTTP/1.1" 301 501 "-" "crusader-worker/1.0"
34.104.154.120 - - [04/Sep/2026:08:10:41 +0000] "GET /html/.git/config HTTP/1.1" 301 497 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇫🇷
Bensay
2026-09-04 04:27:44
(14 hours ago)
HTTP web-app probe; method=GET; path=/api/.git/config; status=403; user-agent=crusader-worker/1.0
Web App Attack
🇩🇪
FD-IX
2026-09-04 01:15:38
(17 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇦
Olexiy Backend
2026-09-03 18:06:28
(1 day ago)
34.104.154.120
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 18:05:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:05:02.445298 2026] [security2:error] [pid 27186:tid 27186] [client 34.104.154.120:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maptshk.365soft.top"] [uri "/app/.git/config"] [unique_id "apm2zgvvbh4L5xWMDndeeQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:28:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:28:10.652019 2026] [security2:error] [pid 30498:tid 30498] [client 34.104.154.120:35524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.serpentstudios.com"] [uri "/.git/config"] [unique_id "apmgGmHImGDmIhiDnvq92AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-03 15:07:49
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇫🇷
Catalin Negru
2026-09-03 06:25:33
(1 day ago)
2026-09-03 09:25:32,863 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 34.104.154.120
2 ...
show more
2026-09-03 09:25:32,863 fail2ban.actions [1796604]: NOTICE [apache-404] Ban 34.104.154.120
2026-09-03 09:25:32,887 fail2ban.actions [1796604]: NOTICE [apache-dirscan] Ban 34.104.154.120
2026-09-03 09:25:33,052 fail2ban.actions [1796604]: NOTICE [apache-security] Ban 34.104.154.120
2026-09-03 09:25:33,053 fail2ban.actions [1796604]: NOTICE [apache-scan] Ban 34.104.154.120
2026-09-03 09:25:33,139 fail2ban.actions [1796604]: NOTICE [web-scanner] Ban 34.104.154.120
...
show less
Brute-Force
Web App Attack
🇵🇱
sefinek.net
2026-09-03 05:15:30
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /var/www/.git/config | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-03 05:10:43
(1 day ago)
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-wo ...
show more
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /app/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.104.154.120 - - [03/Sep/2026:07:10:42 +0200] "GET /site/.git/config HTTP/1.
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 04:28:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.154.120 (120.154.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:28:07.984235 2026] [security2:error] [pid 9021:tid 9029] [client 34.104.154.120:48364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kd2lst.us"] [uri "/api/.git/config"] [unique_id "apj3V-6927fOnLx2fpxvBgAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-03 04:12:42
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇿🇦
conure.sh
2026-09-03 02:07:43
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack