๐ง๐ช
cmbplf
2026-10-05 21:29:00
(6 hours ago)
1.948 requests with url.path */.git/config
703 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Mangelot Hosting
2026-10-05 21:06:57
(6 hours ago)
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 34.178.65.225 (NL/The Netherland ...
show more
(web_sensitive_file) srv104 Sensitive file probe (.env/.git/backup) 34.178.65.225 (NL/The Netherlands/225.65.178.34.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:45:16
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:45:09.965965 2026] [security2:error] [pid 27384:tid 27384] [client 34.178.65.225:57558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtualfresco.com"] [uri "/.git/config"] [unique_id "asQMVTe4V3PloE-sp5wUTAAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 20:27:05
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 16:27:02.099231 2026] [security2:error] [pid 6624:tid 6624] [client 34.178.65.225:50592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virantenn.com"] [uri "/.git/config"] [unique_id "asQIFoe6wet6DG13JY2VRQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-05 19:32:29
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.178.65.225 (225.65.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.178.65.225 (225.65.178.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 19:28:52
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 15:28:47.312629 2026] [security2:error] [pid 2398:tid 2398] [client 34.178.65.225:60178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vintageamptubes.ink2wear.com"] [uri "/.git/config"] [unique_id "asP6b2wXGeo47Lc-_e_cFwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-05 19:05:46
(8 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-05 19:04:41
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Viveronese
2026-10-05 18:55:08
(8 hours ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 18:52:31
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.65.225 (225.65.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 14:52:24.660723 2026] [security2:error] [pid 19822:tid 19822] [client 34.178.65.225:40768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "villamarehiltonhead.com"] [uri "/.git/config"] [unique_id "asPx6OriKHkuo28t2GC4jQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-10-05 18:50:01
(8 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.178.65.225 (NL/The Netherlands/Groningen/G ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.178.65.225 (NL/The Netherlands/Groningen/Groningen/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:49:59.404841 2026] [security2:error] [pid 877609:tid 877654] [client 34.178.65.225:59662] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 225.65.178.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "villa-izabela.com"] [uri "/.git/config"] [unique_id "asPxV-owWM1Dnt-s9AhalAAAAJI"]
show less
Port Scan
๐ฟ๐ฆ
conure.sh
2026-10-05 18:49:34
(8 hours ago)
csagent: score 20.1: secrets grab x2, 404 noise floor x1; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-10-05 18:25:26
(9 hours ago)
fail2ban jail apache-secrets-probe: 34.178.65.225 - - [05/Oct/2026:11:25:24 -0700] "GET /.git/config ...
show more
fail2ban jail apache-secrets-probe: 34.178.65.225 - - [05/Oct/2026:11:25:24 -0700] "GET /.git/config HTTP/1.1" 403 6725 "-" "-"
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-05 18:24:39
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ซ๐ท
Little Iguana
2026-10-05 18:04:11
(9 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking