Anonymous
2026-10-03 13:45:05
(3 hours ago)
Observed scanned 1 known-sensitive endpoint(s), e.g.: /.git/config
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 20:14:03
(21 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ธ๐ช
KIDOS
2026-10-02 20:10:43
(21 hours ago)
KASM auto: exploit_/.git/config
Brute-Force
SSH
๐ณ๐ฑ
Alt255
2026-10-02 20:10:41
(21 hours ago)
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.22.38.38 - - \[02/Oct/2026:22:10:37 +0200\] "GET /.git/config HTTP/1.1" 307 5593 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-02 20:01:19
(21 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-10-02T18:09:50Z
Ray ID: a445a90fefd038e9
UA: Empty string
show less
Bad Web Bot
Anonymous
2026-10-02 20:01:07
(21 hours ago)
34.22.38.38 - - [02/Oct/2026:22:01:07 +0200] "GET /.git/config HTTP/1.1" 404 11812 "-" "-"
...
Brute-Force
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-02 19:58:55
(21 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-02T19:58:52.541950095Z. Context: http_status=404
show less
Web App Attack
๐จ๐ฆ
Anytech
2026-10-02 19:55:28
(21 hours ago)
Blocked by ConnMonitor
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-02 19:53:12
(21 hours ago)
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 34.22.38.38 (US/United States/38 ...
show more
(web_sensitive_file) srv102 Sensitive file probe (.env/.git/backup) 34.22.38.38 (US/United States/38.38.22.34.bc.googleusercontent.com): 2 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
CBJ
2026-10-02 19:37:29
(21 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 19:20:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 15:19:57.437505 2026] [security2:error] [pid 26099:tid 26202] [client 34.22.38.38:37302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpdesign.us"] [uri "/.git/config"] [unique_id "asAD3c7CcA9n15cxLlueBwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 19:13:16
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-02 19:07:14
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:51:57
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:51:51.836519 2026] [security2:error] [pid 5093:tid 5093] [client 34.22.38.38:55104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jmrlighting.com"] [uri "/.git/config"] [unique_id "ar_9R4nnokxUfO5-XDHt-AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 18:35:15
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.38.38 (38.38.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 14:35:10.378410 2026] [security2:error] [pid 32097:tid 32097] [client 34.22.38.38:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jims-bbs.com"] [uri "/.git/config"] [unique_id "ar_5Xqr13Wa_79o512ERHwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack