🇺🇸
Charlesiv
2026-09-07 22:03:15
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-07T20:06:46Z
Ray ID: a37855fa4f3e3969
UA: Empty string
show less
Bad Web Bot
🇩🇪
thesimonmanuel
2026-09-07 20:18:04
(1 day ago)
34.125.138.172 - - [08/Sep/2026:01:48:04 +0530] "GET /.git/config HTTP/1.1" 404 117 "-" "-" "-"
Web App Attack
🇩🇪
pltcldvlpr
2026-09-07 20:14:28
(1 day ago)
CMS/framework probe: 34.125.138.172 - - [07/Sep/2026:22:14:27 +0200] "GET /.git/config HTTP/1.1" 444 ...
show more
CMS/framework probe: 34.125.138.172 - - [07/Sep/2026:22:14:27 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "-" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:54:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:54:16.283427 2026] [security2:error] [pid 20791:tid 20791] [client 34.125.138.172:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "analisis.luisguacache.com"] [uri "/.git/config"] [unique_id "ap8WaMfSpw3NOG5qgNKfAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:30:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:30:46.024376 2026] [security2:error] [pid 31298:tid 31298] [client 34.125.138.172:38754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amybeam.com"] [uri "/.git/config"] [unique_id "ap8Q5leYBVLBEmPIr8kqcAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-07 19:14:17
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-07 19:12:52
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:03:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:03:09.521974 2026] [security2:error] [pid 16473:tid 16473] [client 34.125.138.172:44390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ampstudio.eu"] [uri "/.git/config"] [unique_id "ap8KbSl9EdiFWfFuI7pfpwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-07 19:02:25
(1 day ago)
[07/Sep/2026:22:02:25 +0300] -- 34.125.138.172 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[07/Sep/2026:22:02:25 +0300] -- 34.125.138.172 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-07 18:53:21
(1 day ago)
Blocked by ConnMonitor
Web App Attack
🇸🇪
SkyDancer
2026-09-07 18:48:35
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-07 18:47:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:47:10.174428 2026] [security2:error] [pid 18854:tid 18854] [client 34.125.138.172:33768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amosellistonfortheladies.com"] [uri "/.git/config"] [unique_id "ap8GrliwA3_AVi3p4ATRjAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 18:45:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:08:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.138.172 (172.138.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:08:34.719287 2026] [security2:error] [pid 5482:tid 5482] [client 34.125.138.172:48990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ammatusk.com"] [uri "/.git/config"] [unique_id "ap79otM_MHuunCIQxS08UwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 18:08:19
(1 day ago)
apache vulnerability scan
Web App Attack