🇫🇷
LRob
2026-09-04 22:21:41
(7 minutes ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /.git/config | 2026-09-04 22:21 UTC
show less
Hacking
Web App Attack
🇱🇺
conseilgouz
2026-09-04 22:16:20
(12 minutes ago)
are-17 : Block hidden directories=>/.git/config(/)
Hacking
🇺🇸
TPI-Abuse
2026-09-04 22:10:54
(18 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:10:47.430681 2026] [security2:error] [pid 17373:tid 17373] [client 34.172.32.198:43750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmichaelpope.com"] [uri "/.git/config"] [unique_id "aptB57Fj2VWkJWQ8zhGpyQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-04 21:55:56
(33 minutes ago)
6.565 requests with url.path */.git/config
2.805 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇩🇪
yitzhaq
2026-09-04 21:52:07
(37 minutes ago)
34.172.32.198 - - [04/Sep/2026:23:05:56 +0200] "GET /.git/config HTTP/1.1" 403 4447 "-" "-"
34.172.3 ...
show more
34.172.32.198 - - [04/Sep/2026:23:05:56 +0200] "GET /.git/config HTTP/1.1" 403 4447 "-" "-"
34.172.32.198 - - [04/Sep/2026:21:20:37 +0200] "GET /.git/config HTTP/1.1" 403 4437 "-" "-"
34.172.32.198 - - [04/Sep/2026:23:52:04 +0200] "GET /.git/config HTTP/1.1" 403 4436 "-" "-"
show less
Web App Attack
Hacking
🇺🇸
nyt
2026-09-04 21:48:12
(40 minutes ago)
Sensitive File Probe, Empty UA + 404
Web App Attack
🇩🇪
Phenix Info
2026-09-04 21:44:15
(44 minutes ago)
SmallGuard.fr/Prestashop Empty User Agent
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:35:59
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:35:52.533823 2026] [security2:error] [pid 17632:tid 17647] [client 34.172.32.198:53848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bobchaos.com"] [uri "/.git/config"] [unique_id "aps5uIogxzRn8rLF4OgVOAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 21:01:06
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Lino Project
2026-09-04 20:55:32
(1 hour ago)
34.172.32.198 - - [04/Sep/2026:22:55:29 +0200] "GET /.git/config HTTP/1.1" 403 5314 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:48:14
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:48:11.144392 2026] [security2:error] [pid 18605:tid 18605] [client 34.172.32.198:51200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hardcountryrock.com"] [uri "/.git/config"] [unique_id "apsuiyHGyCw16wPb1Az1HgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-04 20:46:40
(1 hour ago)
trolling for resource vulnerabilities
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-04 20:36:55
(1 hour ago)
[Sat Sep 05 06:36:54.277149 2026] [security2:error] [pid 694115] [client 34.172.32.198:48544] [clien ...
show more
[Sat Sep 05 06:36:54.277149 2026] [security2:error] [pid 694115] [client 34.172.32.198:48544] [client 34.172.32.198] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "apsr5s7uX3tGqGPjqSJcjgAAAAU"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:07:22
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:07:16.745352 2026] [security2:error] [pid 15369:tid 15369] [client 34.172.32.198:55714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.katharinanitzpon.com"] [uri "/.git/config"] [unique_id "apsk9EH0B1zeI4JV8xyqeQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:44:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.172.32.198 (198.32.172.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:44:43.311470 2026] [security2:error] [pid 13421:tid 13421] [client 34.172.32.198:53254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.fritsknuf.com"] [uri "/.git/config"] [unique_id "apsfq3Q8050cidi55AXDlwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack