🇺🇸
TPI-Abuse
2026-09-04 03:11:13
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:11:08.775733 2026] [security2:error] [pid 8084:tid 8084] [client 34.138.59.13:46676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ericdrives.com"] [uri "/.git/config"] [unique_id "apo2zBIrXrsaRYvvl5oBKgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-04 00:20:19
(3 hours ago)
[FriSep0402:20:12.4645552026][security2:error][pid2343652:tid2343679][client34.138.59.13:0]ModSecuri ...
show more
[FriSep0402:20:12.4645552026][security2:error][pid2343652:tid2343679][client34.138.59.13:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"eutecne.ch\"][uri\"/.git/config\"][unique_id\"apoOvB42dlE6x6LdiCaCXwAAANI\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:53:29
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:53:25.530423 2026] [security2:error] [pid 3691:tid 3691] [client 34.138.59.13:38478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daveweisman.com"] [uri "/.git/config"] [unique_id "apoIda55xpQ51ZHBbSJoOgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:17:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:17:45.304335 2026] [security2:error] [pid 24851:tid 24851] [client 34.138.59.13:49938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "equipoperu.org"] [uri "/.git/config"] [unique_id "apoAGf0UoALPhlWMiw7dhgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 22:48:02
(4 hours ago)
Unauthorized SSH login attempts
Brute-Force
SSH
🇺🇸
creechy
2026-09-03 22:24:42
(4 hours ago)
34.138.59.13 - - [03/Sep/2026:15:24:35 -0700] "GET /.git/config HTTP/1.1" 404 767 "-" "Mozilla/5.0 ( ...
show more
34.138.59.13 - - [03/Sep/2026:15:24:35 -0700] "GET /.git/config HTTP/1.1" 404 767 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
🇺🇸
ambor
2026-09-03 22:24:35
(4 hours ago)
Honeypot access: Git configuration file access attempt. Path: /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:47:20
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:47:16.051634 2026] [security2:error] [pid 16696:tid 16696] [client 34.138.59.13:11796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "grabagame.com"] [uri "/.git/config"] [unique_id "apnq5Inbkbgjqf9ZHOV11gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:29:13
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:29:06.335454 2026] [security2:error] [pid 29203:tid 29203] [client 34.138.59.13:21612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fitzmail.com"] [uri "/.git/config"] [unique_id "apnmot1x3vvuwyFCQYhpHQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 20:54:41
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:54:33.612544 2026] [security2:error] [pid 16903:tid 16903] [client 34.138.59.13:63184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dailybeautysupply.com"] [uri "/.git/config"] [unique_id "apneiU69UM7uxPQZGywuRgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 20:13:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.59.13 (13.59.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:13:31.661773 2026] [security2:error] [pid 12376:tid 12376] [client 34.138.59.13:36580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drxcontent.com"] [uri "/.git/config"] [unique_id "apnU65V_bGXTt0XqhgtVnwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-03 19:20:08
(8 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-03 19:12:58
(8 hours ago)
34.138.59.13 - - [03/Sep/2026:21:07:26 +0200] "GET /.git/config HTTP/1.1" 403 4431 "-" "Mozilla/5.0 ...
show more
34.138.59.13 - - [03/Sep/2026:21:07:26 +0200] "GET /.git/config HTTP/1.1" 403 4431 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
34.138.59.13 - - [03/Sep/2026:21:07:26 +0200] "GET /.git/config HTTP/1.1" 301 547 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
34.138.59.13 - - [03/Sep/2026:21:12:54 +0200] "GET /.git/config HTTP/1.1" 403 4437 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
34.138.59.13 - - [03/Sep/2026:10:38:34 +0200] "GET /.git/config HTTP/1.1" 403 4535 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
34.138.59.13 - - [03/Sep/2026:11:46:58 +0200] "GET /.git/config HTTP/1.1" 403 4427 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
Hacking
🇳🇱
BlueWire Hosting
2026-09-03 18:57:24
(8 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇧🇪
cmbplf
2026-09-03 18:52:23
(8 hours ago)
347 requests with url.path */.git/config
Brute-Force
Bad Web Bot