|
Anonymous
|
|
suspicious request in access.log
|
Web App Attack
|
|
|
๐ฎ๐น
madaello
|
|
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /.git/config HTTP/1.1" 404 4592 "-" "Mozilla/4.8 ...
show more
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /.git/config HTTP/1.1" 404 4592 "-" "Mozilla/4.8 [en] (X11; U; SunOS; 5.7 sun4u)"
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 4592 "-" "Baiduspider ( http://www.baidu.com/search/spider.htm)"
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /laravel/.git/config HTTP/1.1" 404 4592 "-" "Mozilla/5.0 (BlackBerry; U; BlackBerry 9800; en) AppleWebKit/534.1 (KHTML, Like Gecko) Version/6.0.0.141 Mobile Safari/534.1"
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /symfony/.git/config HTTP/1.1" 404 4591 "-" "Mozilla/5.0 (Linux; Android 9; VOG-L29) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.22.45.138 - - [15/Jun/2026:04:14:04 +0200] "GET /project/.git/config HTTP/1.1" 404 4593 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36"
...
show less
|
Port Scan
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:09:10.078741 2026] [security2:error] [pid 8451:tid 8451] [client 34.22.45.138:47586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "falundafatr.org"] [uri "/backend/.git/config"] [unique_id "ai9exneEaCq5KbOlyMczTgAAABw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ท
dynamix
|
|
Multiple WAF Violations
|
Web App Attack
|
|
|
๐ฉ๐ช
Philister11
|
|
CrowdSec: crowdsecurity/http-bad-user-agent (US/AS396982)
|
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh_ha-misbehave-ban on chard
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
todix
|
|
WebAttack or semilar from 34.22.45.138
|
Web App Attack
|
|
|
๐ฉ๐ช
enjoyably
|
|
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
|
Web App Attack
Hacking
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:27:28.685088 2026] [security2:error] [pid 11643:tid 11643] [client 34.22.45.138:53734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lewiscountyfair.ewingmissouri.com"] [uri "/app/.git/config"] [unique_id "ai8q0CN3ado2PBS9yzciOAAAACU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
homeshowdomain.nl
|
|
Auto-ban: >3000 req/min op 2026-06-14
|
Web App Attack
SSH
Hacking
|
|
|
๐ฉ๐ช
Marc
|
|
34.22.45.138 - - [14/Jun/2026:23:52:00 +0200] "GET /.git/config HTTP/1.1" 404 3230 "-" "Mozilla/5.0 ...
show more
34.22.45.138 - - [14/Jun/2026:23:52:00 +0200] "GET /.git/config HTTP/1.1" 404 3230 "-" "Mozilla/5.0 (compatible; MSIE 10.6; Windows NT 6.1; Trident/5.0; InfoPath.2; SLCC1; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729; .NET CLR 2.0.50727) 3gpp-gba UNTRUSTED/1.0" 34.22.45.138 - - [14/Jun/2026:23:52:00 +0200] "GET /admin/.git/config HTTP/1.1" 404 3230 "-" "Mozilla/5.0 (Linux; Android 9; SM-G965F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.101 Mobile Safari/537.36" 34.22.45.138 - - [14/Jun/2026:23:52:00 +0200] "GET /code/.git/config HTTP/1.1" 404 3230 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:12.0) Gecko/20120422 Firefox/12.0 SeaMonkey/2.9"
show less
|
Brute-Force
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.45.138 (138.45.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:26:36.752271 2026] [security2:error] [pid 13064:tid 13064] [client 34.22.45.138:57468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beta.instagenii.com"] [uri "/public/.git/config"] [unique_id "ai8cjBbR5vk3QBSszbUyzwAAACg"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ช๐ธ
pipeline.es
|
|
Web scanning / probing for vulnerable paths | URL: /symfony/.git/config | Evidence: rhin.es 34.22.45 ...
show more
Web scanning / probing for vulnerable paths | URL: /symfony/.git/config | Evidence: rhin.es 34.22.45.138 - - [14/Jun/2026:23:01:19 +0200] \"GET /symfony/.git/config HTTP/1.1\" 404 217 \"-\" \"Mozilla/5.0 (Linux; Android 9; moto g(6)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
|
Port Scan
Web App Attack
|
|
|
๐ณ๐ฟ
Antinson
|
|
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
|
Bad Web Bot
|
|
|
๐ณ๐ฑ
Savvii
|
|
20 attempts against mh_ha-misbehave-ban on taro
|
Brute-Force
Bad Web Bot
Web App Attack
|
|