🇺🇸
TPI-Abuse
2026-09-04 22:12:39
(51 seconds ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:12:34.954567 2026] [security2:error] [pid 6368:tid 6368] [client 34.38.98.15:58658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rejuvenationsystems.com"] [uri "/api/.git/config"] [unique_id "aptCUvDAZHoLjgDtstXyWAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:43:49
(29 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:43:44.614809 2026] [security2:error] [pid 1670:tid 1670] [client 34.38.98.15:50238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pittyvaich.com"] [uri "/src/.git/config"] [unique_id "aps7kJ5le4SqkLFMNa6ofwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:43:24
(30 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇨🇭
4server
2026-09-04 19:22:14
(2 hours ago)
[FriSep0421:22:11.6284182026][security2:error][pid1940237:tid1940775][client34.38.98.15:0]ModSecurit ...
show more
[FriSep0421:22:11.6284182026][security2:error][pid1940237:tid1940775][client34.38.98.15:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"swiss-web-hosting-ch.hostingedominio.net\"][uri\"/src/.git/config\"][unique_id\"apsaYweUAdZezRiWq7f9NQAAAJc\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:58:01
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:57:57.479009 2026] [security2:error] [pid 22286:tid 22298] [client 34.38.98.15:57724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.guitarprimer.com"] [uri "/www/.git/config"] [unique_id "apsUtWzz4KYiES1AdcXjtwAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 15:51:13
(6 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-04 13:51:40
(8 hours ago)
[ns41.kdns.gr] httpd-config-scan: sites=www.basoukeasmd.gr; logs=/var/log/httpd/domains/basoukeasmd. ...
show more
[ns41.kdns.gr] httpd-config-scan: sites=www.basoukeasmd.gr; logs=/var/log/httpd/domains/basoukeasmd.gr.log; samples=/src/.git/config | /api/.git/config | /www/.git/config
show less
Hacking
Web App Attack
Anonymous
2026-09-04 13:46:22
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
LRob
2026-09-04 09:58:56
(12 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+11 more) | 2026-09-04 09:58 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:56:19
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:56:11.478183 2026] [security2:error] [pid 3502:tid 3502] [client 34.38.98.15:42980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vanmeter.work"] [uri "/backend/.git/config"] [unique_id "apqVu0zHsLB3n8YqsoJBagAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 09:06:01
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-04 07:36:55
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-04 06:59:29
(15 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:28:55
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:28:49.411939 2026] [security2:error] [pid 22608:tid 22608] [client 34.38.98.15:44162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rgvatvrepair.com"] [uri "/api/.git/config"] [unique_id "appXERl939Y-MLPQ6KVS-gAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:54:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.98.15 (15.98.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:54:35.964317 2026] [security2:error] [pid 6550:tid 6550] [client 34.38.98.15:40506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.picklebillystayandplay.com"] [uri "/htdocs/.git/config"] [unique_id "appPCzizftuwG4_7u0tKjwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack