Anonymous
2026-09-19 20:10:06
(17 minutes ago)
GET /.git/config HTTP/1.1
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 20:09:22
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 16:09:18.493548 2026] [security2:error] [pid 19915:tid 19915] [client 34.145.160.19:56896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rohn.com"] [uri "/.git/config"] [unique_id "aq7r7tyG179OwPfJ3nEHgAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-09-19 19:43:00
(44 minutes ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:40:32
(46 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:40:26.094306 2026] [security2:error] [pid 28343:tid 28343] [client 34.145.160.19:47028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rocketcityhotwheelers.com"] [uri "/.git/config"] [unique_id "aq7lKvje4MIM_QgZVyJ14QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-09-19 19:21:10
(1 hour ago)
[REDACTED] 34.145.160.19 - - [19/Sep/2026:21:21:10 +0200] "GET /.git/config HTTP/1.1" 404 4521 "-" " ...
show more
[REDACTED] 34.145.160.19 - - [19/Sep/2026:21:21:10 +0200] "GET /.git/config HTTP/1.1" 404 4521 "-" "-"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 19:18:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 15:18:05.894626 2026] [security2:error] [pid 32028:tid 32028] [client 34.145.160.19:60634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.robin5on.com"] [uri "/.git/config"] [unique_id "aq7f7ZQg4LHLxrdu5rLvKAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-19 19:04:49
(1 hour ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-19 18:52:54
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.145.160.19 (US/United States/19. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.145.160.19 (US/United States/19.160.145.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:43:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:43:51.767423 2026] [security2:error] [pid 16050:tid 16050] [client 34.145.160.19:41972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srippy.com"] [uri "/.git/config"] [unique_id "aq7X5-9KV6G5yGwX93g_wQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
P1n4
2026-09-19 18:40:45
(1 hour ago)
Heimdal IDS auto-block: sensitive_file (score=0.90)
Web App Attack
Anonymous
2026-09-19 18:25:04
(2 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-19 18:06:18
(2 hours ago)
csagent: score 20.0: secrets grab x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:04:45
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:04:40.096943 2026] [security2:error] [pid 22003:tid 22003] [client 34.145.160.19:48030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spottedeaglearts.com"] [uri "/.git/config"] [unique_id "aq7OuEM5v2kA2ikOCh0GygAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-19 17:49:27
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:29:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.160.19 (19.160.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:29:18.739568 2026] [security2:error] [pid 20996:tid 20996] [client 34.145.160.19:55392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.spittingimageprint.kathrynmcbride.com"] [uri "/.git/config"] [unique_id "aq7GbuSuxrzqsjJa29X_zwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack