Anonymous
2026-07-29 07:00:00
(6 hours ago)
Apache probe; attempts=72; exact paths: /.git/config
Web App Attack
Anonymous
2026-07-29 06:07:33
(7 hours ago)
Trying to access config files
Web App Attack
๐ฎ๐ณ
evicky2002
2026-07-28 06:00:00
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-28 02:08:01
(1 day ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,ice02]
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 01:28:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:28:34.718616 2026] [security2:error] [pid 173075:tid 173075] [client 34.181.208.39:33980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tourissue.com"] [uri "/.git/config"] [unique_id "amgFwiuj3jWdZcjtwdSVcgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-07-28 01:28:15
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-07-28 01:27:36
(1 day ago)
34.181.208.39 - - [28/Jul/2026:04:27:35 +0300] "GET /.git/config HTTP/1.1" 404 4704 "-" "-"
...
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-28 01:07:01
(1 day ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [mx02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Rip
2026-07-28 01:05:27
(1 day ago)
Restricted File Access Attempts
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 00:54:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:54:08.948624 2026] [security2:error] [pid 1263476:tid 1263476] [client 34.181.208.39:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totalsafe-security.com"] [uri "/.git/config"] [unique_id "amf9sBQ6fCarZEwpwTxmtQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 00:32:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:32:32.417130 2026] [security2:error] [pid 828890:tid 828890] [client 34.181.208.39:50854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tortoisehosting.com"] [uri "/.git/config"] [unique_id "amf4oAMuSXygghKrkE4usAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-07-28 00:24:49
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Empty string โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
etu brutus
2026-07-28 00:06:29
(1 day ago)
34.181.208.39 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
Charlesiv
2026-07-28 00:02:49
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-07-27T22:32:50Z
Ray ID: a21f1a33f90d90ac
UA: Empty string
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 23:49:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.208.39 (39.208.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:49:04.162722 2026] [security2:error] [pid 371388:tid 371388] [client 34.181.208.39:52544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toptek.com"] [uri "/.git/config"] [unique_id "amfucNMEqbVOm7yvVTw0-gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack