🇺🇸
TPI-Abuse
2026-09-07 23:26:01
(1 minute ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:25:55.569101 2026] [security2:error] [pid 22269:tid 22269] [client 34.156.92.192:42772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.bbernal.com"] [uri "/.git/config"] [unique_id "ap9IA-490YNpfV4oC6XOFgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-07 23:08:01
(19 minutes ago)
(mod_security-custom) mod_security (id:210492) triggered by 34.156.92.192 (BE/Belgium/Brussels Capit ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 34.156.92.192 (BE/Belgium/Brussels Capital/Brussels/192.92.156.34.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
🇬🇧
AvonleaConsulting
2026-09-07 22:58:46
(28 minutes ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:49:33
(38 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:49:29.770961 2026] [security2:error] [pid 25849:tid 25849] [client 34.156.92.192:46240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "804websolutions.com"] [uri "/.git/config"] [unique_id "ap8_eXdzF8wi2WriZCwvBgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 22:05:10
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:05:02.592546 2026] [security2:error] [pid 14247:tid 14247] [client 34.156.92.192:42352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.volunteergems.com"] [uri "/.git/config"] [unique_id "ap81DoXoWyf_IsP1MHXKZAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:46:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:46:02.443285 2026] [security2:error] [pid 18670:tid 18670] [client 34.156.92.192:37142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citati.net"] [uri "/.git/config"] [unique_id "ap8wmlVD9jpJwQx2mltBtwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
AvonleaConsulting
2026-09-07 21:43:28
(1 hour ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:09:49
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:09:43.272392 2026] [security2:error] [pid 2418370:tid 2418370] [client 34.156.92.192:38990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.lloydprins.com"] [uri "/.git/config"] [unique_id "ap8oF5J81TmsbDYrp1wLKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
YF
2026-09-07 21:00:37
(2 hours ago)
Git config exposure probe
Web App Attack
🇳🇴
jad-abuse
2026-09-07 20:44:01
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
Anonymous
2026-09-07 20:40:02
(2 hours ago)
suspicious request in access.log
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-07 20:21:55
(3 hours ago)
[07/Sep/2026:23:21:55 +0300] -- 34.156.92.192 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[07/Sep/2026:23:21:55 +0300] -- 34.156.92.192 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:17:58
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:17:52.028520 2026] [security2:error] [pid 8360:tid 8360] [client 34.156.92.192:50352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cidv.net"] [uri "/.git/config"] [unique_id "ap8b8ACCqbDYQ1qMohxSRwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:37:16
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.92.192 (192.92.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:37:10.232331 2026] [security2:error] [pid 14819:tid 14839] [client 34.156.92.192:45292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalbusinesscollege.com"] [uri "/.git/config"] [unique_id "ap8SZpilbNLfAA2ZP61aOAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-07 19:15:03
(4 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack