๐ง๐ช
cmbplf
2026-09-24 11:50:50
(1 week ago)
351 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-09-24 09:00:09
(1 week ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 08:31:36
(1 week ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /app/.git/config (+11 more) | 2026-09-24 08:31 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:27:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:27:28.101657 2026] [security2:error] [pid 22044:tid 22044] [client 34.39.249.30:36756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.pamplonaserviciotecnico.com"] [uri "/backend/.git/config"] [unique_id "arSKkKtIipA4Y5pC0KF9uwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:03:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:03:03.398945 2026] [security2:error] [pid 32193:tid 32261] [client 34.39.249.30:40844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.priyom.us"] [uri "/htdocs/.git/config"] [unique_id "arR2x9_9WU-96geH2uSBTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 22:50:34
(1 week ago)
[24/Sep/2026:01:50:34 +0300] -- 34.39.249.30 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[24/Sep/2026:01:50:34 +0300] -- 34.39.249.30 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:31:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:31:48.146741 2026] [security2:error] [pid 3105380:tid 3105380] [client 34.39.249.30:53028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "commercialvacuumsealer.com"] [uri "/site/.git/config"] [unique_id "arRTVBO2TkKuKzGZ4HVTngAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 22:01:23
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 21:10:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:10:15.476183 2026] [security2:error] [pid 14048:tid 14048] [client 34.39.249.30:51058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloggersunlimited.com"] [uri "/api/.git/config"] [unique_id "arRANzWrFMm8NdVTyjsdSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 19:48:20
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-09-23 17:34:29
(1 week ago)
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /site/.git/config HTTP/1.1" 444 0 "-" "crusader-w ...
show more
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /site/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /app/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /src/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /htdocs/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.39.249.30 - - [23/Sep/2026:14:34:29 -0300] "GET /html/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:29:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:29:17.556651 2026] [security2:error] [pid 4410:tid 4410] [client 34.39.249.30:53062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carpentriesoffline.org.jannetta.com"] [uri "/src/.git/config"] [unique_id "arQMbYikmxQdWYgVRjGaGwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:57:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.249.30 (30.249.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:57:04.663967 2026] [security2:error] [pid 32717:tid 32717] [client 34.39.249.30:56930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canadagreenrecycling.com"] [uri "/backend/.git/config"] [unique_id "arQE4ADHutfN-sZMDnWKUAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 15:04:48
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-23 14:25:23
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack