🇺🇸
OceanTreasure
2026-09-07 21:35:11
(9 minutes ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-09-07T21:34:11Z [proxy]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:23:46
(21 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:23:39.397306 2026] [security2:error] [pid 5632:tid 5632] [client 34.187.28.180:43636] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.exorex.com"] [uri "/.git/config"] [unique_id "ap8rW2w8VMy6SCepYAA8pQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:07:34
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:07:29.877802 2026] [security2:error] [pid 2945:tid 2945] [client 34.187.28.180:34336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maprada92.com"] [uri "/.git/config"] [unique_id "ap8nkWAhUZfp0v74ynIWcgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:51:11
(53 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:51:04.881093 2026] [security2:error] [pid 2397292:tid 2397292] [client 34.187.28.180:40912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kentuckyminiaturehorsebreeders.org"] [uri "/.git/config"] [unique_id "ap8juPlsPk1BBMmZGPF5xwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:21:38
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:21:32.014775 2026] [security2:error] [pid 22665:tid 22665] [client 34.187.28.180:51142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [uri "/.git/config"] [unique_id "ap8czN_46vUwyfLefK_EdAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
www.winos.me
2026-09-07 20:10:23
(1 hour ago)
Scanning for sensitive files/paths: /.git/config
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-07 20:08:38
(1 hour ago)
[07/Sep/2026:23:08:38 +0300] -- 34.187.28.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[07/Sep/2026:23:08:38 +0300] -- 34.187.28.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:02:56
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:02:48.680689 2026] [security2:error] [pid 18390:tid 18390] [client 34.187.28.180:49382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.barkatthemoonpetsitting.com"] [uri "/.git/config"] [unique_id "ap8YaLc4kK5FXQ5ANPFXDwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-07 20:01:31
(1 hour ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:46:52
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:46:47.398487 2026] [security2:error] [pid 27437:tid 27437] [client 34.187.28.180:54434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kentsavagelaw.com"] [uri "/.git/config"] [unique_id "ap8UpwY6eQscqxxExAgxPgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 19:23:49
(2 hours ago)
fail2ban jail apache-secrets-probe: startupian.com:443 34.187.28.180 - - [07/Sep/2026:12:23:48 -0700 ...
show more
fail2ban jail apache-secrets-probe: startupian.com:443 34.187.28.180 - - [07/Sep/2026:12:23:48 -0700] "GET /.git/config HTTP/1.1" 301 4557 "-" "Mozilla/5.0 (Linux; Android 15; SM-S928B) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Mobile Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:19:23
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.28.180 (180.28.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:19:15.318061 2026] [security2:error] [pid 19793:tid 19800] [client 34.187.28.180:39920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deathbyaudiostore.com"] [uri "/.git/config"] [unique_id "ap8OM4MT5RobvYSQfLGlSgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-09-07 19:19:03
(2 hours ago)
HTTP vulnerability scanning
Web App Attack
🇩🇪
iNetWorker
2026-09-07 19:04:15
(2 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 19:00:35
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack