๐บ๐ธ
TPI-Abuse
2026-05-23 22:01:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 18:01:15.417080 2026] [security2:error] [pid 12859:tid 12859] [client 34.176.48.112:34706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.surf-sci-eng.com"] [uri "/.git/config"] [unique_id "ahIjqxlsVWk8Ga6mG_BgwwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-05-23 21:52:31
(1 week ago)
[SatMay2323:52:26.9707882026][security2:error][pid1579290:tid1579359][client34.176.48.112:0]ModSecur ...
show more
[SatMay2323:52:26.9707882026][security2:error][pid1579290:tid1579359][client34.176.48.112:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ftp.ci-ticino.ch\"][uri\"/.git/config\"][unique_id\"ahIhmqEixTXbokQrK2LAdQAAAIg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ญ๐บ
bcsaba
2026-05-23 21:21:54
(1 week ago)
Probing for .git:
34.176.48.112 - - [23/May/2026:23:21:53 +0200] "GET /.git/config HTTP/1.1" 400 632 ...
show more
Probing for .git:
34.176.48.112 - - [23/May/2026:23:21:53 +0200] "GET /.git/config HTTP/1.1" 400 632 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.145 Safari/537.36 Vivaldi/2.6.1566.49"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 20:23:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 16:23:26.033193 2026] [security2:error] [pid 8576:tid 8576] [client 34.176.48.112:35684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.thewarmachineguns.com"] [uri "/.git/config"] [unique_id "ahIMvoxNmT3bVoNLFPXzMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 18:58:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 14:58:21.011972 2026] [security2:error] [pid 30708:tid 30726] [client 34.176.48.112:56576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "api-preview-euw2.cargowebstore.com"] [uri "/.git/config"] [unique_id "ahH4zaFhchzqfjpAXCZdEwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-05-23 18:42:31
(1 week ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensiti ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: sensitive_files (Sensitive files, source control, config, and backups). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-05-23 18:24:21
(1 week ago)
34.176.48.112 - - [23/May/2026:20:24:20 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 ...
show more
34.176.48.112 - - [23/May/2026:20:24:20 +0200] "GET /.git/config HTTP/1.1" 200 265 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/64.0.3282.186 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 18:00:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 14:00:24.276067 2026] [security2:error] [pid 4904:tid 4904] [client 34.176.48.112:40950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.drunkenmonkeystyle.com"] [uri "/.git/config"] [unique_id "ahHrOB9e8az-1CrMkgDU7QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 17:19:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 13:19:17.827291 2026] [security2:error] [pid 22472:tid 22472] [client 34.176.48.112:32816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.rockinr.org"] [uri "/.git/config"] [unique_id "ahHhlX3yzzrRIyjjUNGmyAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-05-23 17:18:44
(1 week ago)
/.git/config
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-23 16:12:37
(1 week ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
Anonymous
2026-05-23 16:05:40
(1 week ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 15:20:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 11:20:53.602062 2026] [security2:error] [pid 23208:tid 23208] [client 34.176.48.112:38394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.vmmailing.com"] [uri "/.git/config"] [unique_id "ahHF1SlDbN3yE_8BazWWogAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 14:53:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 10:53:25.912934 2026] [security2:error] [pid 24282:tid 24282] [client 34.176.48.112:50478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.aprilparks.com"] [uri "/.git/config"] [unique_id "ahG_ZTk3xS5nLaE60wzB1QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 14:03:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.48.112 (112.48.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 10:03:26.010297 2026] [security2:error] [pid 10220:tid 10220] [client 34.176.48.112:38430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.casaconnell.com"] [uri "/.git/config"] [unique_id "ahGzrpyLLvDlrpXdQpCQ2gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack