๐ณ๐ด
jad-abuse
2026-06-15 01:02:52
(36 minutes ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 30 hits.
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 00:41:19
(57 minutes ago)
Try to access /frontend/.git/config
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 00:32:21
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:31:28
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:31:24.833611 2026] [security2:error] [pid 11015:tid 11015] [client 34.174.95.253:51040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "micaden.com.marshvineyards.com"] [uri "/src/.git/config"] [unique_id "ai9H3J0Yq6RG6LXy-PEuMwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
NihiliousMonk
2026-06-15 00:30:30
(1 hour ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 00:10:03
(1 hour ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-06-15 00:09:43
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.174.95.253 (US/United States/253.95. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.174.95.253 (US/United States/253.95.174.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
mnsf
2026-06-15 00:07:52
(1 hour ago)
Abuse Detected (51)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:58:29
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:58:23.284011 2026] [security2:error] [pid 21019:tid 21019] [client 34.174.95.253:58040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "psicotanato.com.elpais.mx"] [uri "/app/.git/config"] [unique_id "ai9AH-Rd1PwXxT1USgvUTAAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-06-14 23:16:38
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 22:56:58
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.174.95.253 (253.95.174.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.174.95.253 (253.95.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:56:52.161568 2026] [security2:error] [pid 24894:tid 24894] [client 34.174.95.253:39340] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sunstrongmetal.com"] [uri "/v1/.git/config"] [unique_id "ai8xtMwtnoobtfLQWBXvRAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:27:15
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.95.253 (253.95.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:27:07.798613 2026] [security2:error] [pid 13077:tid 13093] [client 34.174.95.253:44438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coloradospringsmohs.com"] [uri "/app/.git/config"] [unique_id "ai8quzljnKuiUL3DxBbBbQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-14 22:03:01
(3 hours ago)
Auto-ban: >3000 req/min op 2026-06-14
Web App Attack
SSH
Hacking
๐จ๐ญ
Origon
2026-06-14 21:37:02
(4 hours ago)
http-sensitive-files - IP: 34.174.95.253 - time="2026-06-14T23:37:01+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.174.95.253 - time="2026-06-14T23:37:01+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.174.95.253 (US/396982) : 4h ban on Ip 34.174.95.253" module=db
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-14 21:35:15
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /html/.git/config
UA: Mozilla/5.0 (X11; Linux x86_64; rv:2.0.1) Gecko/20100101 Firefox/4.0.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot