Anonymous
2026-08-29 00:32:05
(19 minutes ago)
Bot / scanning and/or hacking attempts: GET /api/.git/config HTTP/1.1, GET /html/.git/config HTTP/1. ...
show more
Bot / scanning and/or hacking attempts: GET /api/.git/config HTTP/1.1, GET /html/.git/config HTTP/1.1, GET /backend/.git/config HTTP/1.1, GET /src/.git/config HTTP/1.1, GET /app/.git/config HTTP/1.1, GET /www/.git/config HTTP/1.1, GET /.git/config HTTP/1.1, GET /htdocs/.git/config HTTP/1.1, GET /var/www/.git/config HTTP/1.1
show less
Hacking
Web App Attack
π«π·
masterguru
2026-08-29 00:05:46
(45 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-08-29 00:00:08
(51 minutes ago)
suspicious request in access.log
Web App Attack
π³π±
homeshowdomain.nl
2026-08-28 21:59:20
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 21:34:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:34:01.171347 2026] [security2:error] [pid 3185:tid 3185] [client 34.105.158.201:52634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angelsofrhodeisland.com.alanmariotti.com"] [uri "/.git/config"] [unique_id "apH-ybWPD5GfIdFhE3zQgQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-08-28 21:24:56
(3 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 17:45:54
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:45:49.518679 2026] [security2:error] [pid 27578:tid 27578] [client 34.105.158.201:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.webuildbeaches.com"] [uri "/site/.git/config"] [unique_id "apHJTSd1nHgdAFVXcQjSHAAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 16:50:35
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:50:29.375684 2026] [security2:error] [pid 27663:tid 27663] [client 34.105.158.201:42268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.doncody.disio.com"] [uri "/www/.git/config"] [unique_id "apG8Vc1vC_gYCRQ8q87p2wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 15:44:13
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:44:06.120312 2026] [security2:error] [pid 13096:tid 13096] [client 34.105.158.201:48936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.250cabrini.steambalancing.com"] [uri "/.git/config"] [unique_id "apGsxiSd3PYPKAQffILEhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-08-28 14:31:53
(10 hours ago)
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints ( ...
show more
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
show less
Bad Web Bot
πΊπΈ
FreeMyIP
2026-08-28 13:57:34
(10 hours ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack
πΏπ¦
conure.sh
2026-08-28 11:54:46
(12 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
π«π·
masterguru
2026-08-28 11:52:34
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 11:33:57
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.105.158.201 (201.158.105.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:33:52.891962 2026] [security2:error] [pid 1840927:tid 1840977] [client 34.105.158.201:47000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deepwaterdock.nicholsinvest.com"] [uri "/wordpress/.git/config"] [unique_id "apFyINHc4a-9vENlTaREpwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-27 17:05:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack