Anonymous
2025-06-10 04:54:12
(1 year ago)
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/H ...
show more
fail2ban_an apache-modsecurity [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/HEAD"]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
COMPLEX
2025-06-10 00:34:30
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (GOOGLE-CLOUD-PLA ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (GOOGLE-CLOUD-PLATFORM)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
show less
Bad Web Bot
Anonymous
2025-06-09 23:18:33
(1 year ago)
Bot / scanning and/or hacking attempts: GET /.git/HEAD HTTP/1.1, GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-09 22:46:33
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 18:46:27.520660 2025] [security2:error] [pid 150771:tid 150771] [client 34.162.126.248:42756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.owlcapone.com"] [uri "/.git/HEAD"] [unique_id "aEdkQ6xBSclEOwcIHeabugAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-09 17:34:56
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 13:34:51.870022 2025] [security2:error] [pid 2394460:tid 2394460] [client 34.162.126.248:56206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forestvalleyfarm.com"] [uri "/.git/HEAD"] [unique_id "aEcbO_lWq4JjreZ5GrnBLgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sthoyer.de
2025-06-09 15:08:03
(1 year ago)
34.162.126.248 - - [09/Jun/2025:17:08:02 +0200] "GET /.git/config HTTP/1.1" 404 711 "-" "ct\xe2\x80\ ...
show more
34.162.126.248 - - [09/Jun/2025:17:08:02 +0200] "GET /.git/config HTTP/1.1" 404 711 "-" "ct\xe2\x80\x91git\xe2\x80\x91scanner/0.4"
34.162.126.248 - - [09/Jun/2025:17:08:02 +0200] "GET /.git/HEAD HTTP/1.1" 404 711 "-" "ct\xe2\x80\x91git\xe2\x80\x91scanner/0.4"
34.162.126.248 - - [09/Jun/2025:17:08:02 +0200] "GET /.git/HEAD HTTP/1.1" 404 711 "-" "ct\xe2\x80\x91git\xe2\x80\x91scanner/0.4"
...
show less
Web App Attack
Anonymous
2025-06-09 10:35:03
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2025-06-09 09:01:24
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 05:01:16.344446 2025] [security2:error] [pid 3381980:tid 3381980] [client 34.162.126.248:46222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lizlemos.org"] [uri "/.git/HEAD"] [unique_id "aEai3GWdI0C7KsKAq84bAAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
marcel-knorr.de
2025-06-09 08:16:57
(1 year ago)
[MK-Root1] Blocked by UFW
Port Scan
Brute-Force
๐ฉ๐ช
FeG Deutschland
2025-06-09 07:18:54
(1 year ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-09 07:02:43
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.162.126.248 (248.126.162.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 03:02:36.660192 2025] [security2:error] [pid 389264:tid 389264] [client 34.162.126.248:55444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "misterflores.com"] [uri "/.git/HEAD"] [unique_id "aEaHDDyHKb9mr1Q3y8ug0AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2025-06-09 06:53:14
(1 year ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.162.126.248 (US/United States/24 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.162.126.248 (US/United States/248.126.162.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
gumbysoft
2025-06-09 06:17:45
(1 year ago)
Unauthorized web vulnerability scan (/.env, wordpress, etc.)
Web App Attack
๐ซ๐ท
dynamix
2025-06-09 05:15:38
(1 year ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2025-06-09 00:35:14
(1 year ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack