๐ง๐ช
cmbplf
2026-06-15 05:33:18
(14 minutes ago)
1.193 requests with url.path */.git/config
Brute-Force
Bad Web Bot
Anonymous
2026-06-15 04:25:01
(1 hour ago)
suspicious request in access.log
Web App Attack
๐ฎ๐น
NonOggiCaroMio
2026-06-15 04:00:27
(1 hour ago)
Arruso ca si: crowdsecurity/http-sensitive-files
Brute-Force
๐ซ๐ท
masterguru
2026-06-15 03:56:20
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:39:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:39:10.070424 2026] [security2:error] [pid 4768:tid 4768] [client 34.40.188.97:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thectegroup.net"] [uri "/.git/config"] [unique_id "ai9z3p7BEzIUDD4NriIR7AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 02:28:13
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
4server
2026-06-15 02:24:50
(3 hours ago)
[MonJun1504:24:45.9197202026][security2:error][pid3338868:tid3338888][client34.40.188.97:0]ModSecuri ...
show more
[MonJun1504:24:45.9197202026][security2:error][pid3338868:tid3338888][client34.40.188.97:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.danielasilvia.ch.136-243-54-122.cpanel.site\"][uri\"/htdocs/.git/config\"][unique_id\"ai9ibZ3wLQBVKk8VEJlddQAAARA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-15 02:17:48
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /web/.git/config | Evidence: fstravel.pt 34.40.18 ...
show more
Web scanning / probing for vulnerable paths | URL: /web/.git/config | Evidence: fstravel.pt 34.40.188.97 - - [15/Jun/2026:04:17:41 +0200] \"GET /web/.git/config HTTP/1.1\" 404 20857 \"-\" \"Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:35.0) Gecko/20100101 Firefox/35.0\" GEOIP_COUNTRY_CODE=AU | ASN: GOOGLE-CLOUD-PLATFORM | Country: AU
show less
Port Scan
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2026-06-15 01:36:34
(4 hours ago)
Scanning for web/db/file exploits on speakerland.nl
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:04:57
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:04:51.507074 2026] [security2:error] [pid 10700:tid 10743] [client 34.40.188.97:48402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.waqm.org.aafm.us"] [uri "/.git/config"] [unique_id "ai9Ps-_Ur0mU4xGvlGhr-AAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-15 00:20:35
(5 hours ago)
Web vulnerability probing: /dashboard/.git/config
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-15 00:19:20
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
mnsf
2026-06-15 00:19:10
(5 hours ago)
Too many Status 40X (11)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:18:43
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.188.97 (97.188.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:18:39.522162 2026] [security2:error] [pid 16729:tid 16729] [client 34.40.188.97:48982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.actionrevshop.mainstreetofficesuites.com"] [uri "/frontend/.git/config"] [unique_id "ai9E31z2i0rqhQJwXIHVGwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-15 00:16:29
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack