🇳🇱
javierin
2026-09-04 13:58:07
(1 day ago)
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /site/.git/config HTTP/1.1" 4 ...
show more
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /site/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /src/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /var/www/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /public/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /app/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /api/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:58:06 +0000] "GET /www/.git/config HTTP/1.1" 404 16999 "-" "crusader-worker/1.0"
34.181.201.179 - xn--emas-sra.es - - [04/Sep/2026:13:5
...
show less
Hacking
Web App Attack
Anonymous
2026-09-04 12:07:48
(1 day ago)
Scenarios: http-probing, http-sensitive-files
Total requests: 24
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:10
(1 day ago)
Too many Status 40X (11)
Scanning/Probing (22)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:55:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:55:11.424574 2026] [security2:error] [pid 10804:tid 11076] [client 34.181.201.179:60390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adprospb.com"] [uri "/api/.git/config"] [unique_id "apqxn3e6a7HOMWDEtBx5vgAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dave
2026-09-04 11:24:12
(2 days ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/vpatch-git-config observed_by=1_hosts hit_count=12 first_seen=2026-09-04T11:24:12Z last_seen=2026-09-04T11:24:12Z
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:23:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:23:31.506728 2026] [security2:error] [pid 23709:tid 23709] [client 34.181.201.179:35266] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foro.vientodelevante.es"] [uri "/site/.git/config"] [unique_id "apqqM8fEkrhsINap-qTd6QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 09:09:43
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.181.201.179 (US/United States/179.201.181.34 ...
show more
(mod_security) mod_security (id:949110) triggered by 34.181.201.179 (US/United States/179.201.181.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇫🇷
masterguru
2026-09-04 07:31:49
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇩🇪
IVski.com
2026-09-04 06:36:30
(2 days ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-04 06:24:21
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 05:35:25
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇭🇺
bcsaba
2026-09-04 02:11:29
(2 days ago)
Probing for .git:
34.181.201.179 - - [04/Sep/2026:04:11:27 +0200] "GET /.git/config HTTP/1.1" 400 23 ...
show more
Probing for .git:
34.181.201.179 - - [04/Sep/2026:04:11:27 +0200] "GET /.git/config HTTP/1.1" 400 230 "-" "crusader-worker/1.0"
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-04 01:32:21
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:16:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:16:25.511668 2026] [security2:error] [pid 22537:tid 22537] [client 34.181.201.179:35034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "foamnoodlejousting.com"] [uri "/src/.git/config"] [unique_id "apoN2TEKEqTx0aRs0QMzWwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 18:20:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.201.179 (179.201.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:20:26.522507 2026] [security2:error] [pid 28478:tid 28478] [client 34.181.201.179:51646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mandytony.tonylai.com"] [uri "/html/.git/config"] [unique_id "apm6asHyEwq9jXsN-wkd4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack