๐บ๐ธ
TPI-Abuse
2026-09-23 21:23:07
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:23:02.901807 2026] [security2:error] [pid 30427:tid 30427] [client 34.26.123.158:52230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "productosdelimpiezamagiccleannayarit.com"] [uri "/.git/config"] [unique_id "arRDNvpJiTox3qRpIMR-egAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 20:56:58
(3 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:55:33
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:55:30.297163 2026] [security2:error] [pid 2699:tid 2699] [client 34.26.123.158:33176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "prodigypartners.prodigyventure.com"] [uri "/.git/config"] [unique_id "arQ8woVJs9Wu1kkUnH0c5AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:36:14
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:36:08.240841 2026] [security2:error] [pid 2986037:tid 2986037] [client 34.26.123.158:54350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "procurement.ic1.biz"] [uri "/.git/config"] [unique_id "arQ4OO0OTURzIe5fP7h88QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 20:32:10
(3 hours ago)
[23/Sep/2026:23:32:10 +0300] -- 34.26.123.158 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[23/Sep/2026:23:32:10 +0300] -- 34.26.123.158 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:54:41
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:54:37.284608 2026] [security2:error] [pid 31857:tid 31857] [client 34.26.123.158:56672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "r-390.com"] [uri "/.git/config"] [unique_id "arQufZ-n8MWjBKHfAxLu1gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
mscode.pl
2026-09-23 19:49:52
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: r2.lsstories.com
Endpoint: /.git/config
UA: Empty string
show less
Bad Web Bot
๐ซ๐ฎ
as211431.net
2026-09-23 19:41:51
(4 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ฐ
toolbit.online
2026-09-23 18:00:05
(6 hours ago)
Automated scan for common CMS/admin/secrets-exposure paths (WordPress/Joomla/phpMyAdmin/.env/.git/cg ...
show more
Automated scan for common CMS/admin/secrets-exposure paths (WordPress/Joomla/phpMyAdmin/.env/.git/cgi-bin and similar) that do not exist on this server - all requests 404'd, volume stayed below any automatic ban threshold.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:51:38
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:51:33.863965 2026] [security2:error] [pid 23428:tid 23428] [client 34.26.123.158:57522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qwik-wash.com"] [uri "/.git/config"] [unique_id "arQRpUktbWKl-zNc44XSfwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-23 15:47:07
(8 hours ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-23 15:40:02
(8 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:37:22
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.123.158 (158.123.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:37:16.002461 2026] [security2:error] [pid 31542:tid 31542] [client 34.26.123.158:48074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "site.ablogisticsgroup.com"] [uri "/.git/config"] [unique_id "arPyLFOQY-OcWYri-XbYJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 15:31:53
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-23 15:31:31
(8 hours ago)
Try to access /.git/config
Web App Attack