Anonymous
2026-09-21 04:17:19
(2 days ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-21 00:49:20
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 00:22:43
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ง๐ท
dominioz
2026-09-20 22:51:04
(2 days ago)
2026-09-20 22:50:54 GET /.git/config - - 34.19.230.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+Apple ...
show more
2026-09-20 22:50:54 GET /.git/config - - 34.19.230.79 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 474
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-20 21:54:18
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ซ๐ท
breubit
2026-09-20 21:30:22
(2 days ago)
34.19.230.79 - - [20/Sep/2026:23:30:22 +0200] "GET /.git/config HTTP/1.1" 404 522 "-" "Mozilla/5.0 ( ...
show more
34.19.230.79 - - [20/Sep/2026:23:30:22 +0200] "GET /.git/config HTTP/1.1" 404 522 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-20 21:19:44
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.19.230.79 (CA/Canada/79.230.19.34.bc.googleu ...
show more
(mod_security) mod_security (id:949110) triggered by 34.19.230.79 (CA/Canada/79.230.19.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:12:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:12:37.014711 2026] [security2:error] [pid 10628:tid 10628] [client 34.19.230.79:42996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julieknightbooks.com"] [uri "/.git/config"] [unique_id "arBMRSbEwFlYLGQOAvDzZAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:15:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:14:55.462171 2026] [security2:error] [pid 31268:tid 31268] [client 34.19.230.79:51274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juliataylor.us"] [uri "/.git/config"] [unique_id "arA-v_b5cv_SNwtgmp5PGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 19:42:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 15:41:57.207155 2026] [security2:error] [pid 18037:tid 18039] [client 34.19.230.79:38196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julianositalianrestaurant.com"] [uri "/.git/config"] [unique_id "arA3BdPV6kGcQZyOtDzK7AAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:15:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:15:07.673467 2026] [security2:error] [pid 15773:tid 15773] [client 34.19.230.79:48512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "juliagouge.benshermanguitar.com"] [uri "/.git/config"] [unique_id "arAiqyApToW5ul6ynOV0VQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 17:37:05
(2 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.19.230.79 - - [20/Sep/2026:19:36:45 +0200] "GET /.git/config HTTP/1.1" 404 2105 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-20 16:56:19
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 514 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:49:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.19.230.79 (79.230.19.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:49:30.807919 2026] [security2:error] [pid 26431:tid 26431] [client 34.19.230.79:60400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julecarey.com"] [uri "/.git/config"] [unique_id "arAOmuV-tNnEWKeRjKav8wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-20 16:30:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack