Anonymous
2026-10-06 19:39:29
(2 days ago)
Web Server Exposed Git Repository Information Disclosure.
Hacking
πΊπΈ
TPI-Abuse
2026-10-06 19:32:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:31:56.125448 2026] [security2:error] [pid 5060:tid 5060] [client 34.42.208.135:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "site.kimbrothersusa.com"] [uri "/.git/config"] [unique_id "asVMrEWUKP_M3RyX0oWQ4QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-10-06 19:21:20
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-10-06 19:21:04
(2 days ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 19:15:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:15:45.511438 2026] [security2:error] [pid 7771:tid 7771] [client 34.42.208.135:34982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sistema.tritec.com.gt"] [uri "/.git/config"] [unique_id "asVI4S0Co8HmHC7vaBbX3QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 19:05:33
(2 days ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 19:00:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:00:41.379439 2026] [security2:error] [pid 21759:tid 21759] [client 34.42.208.135:40736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sirio-b.com"] [uri "/.git/config"] [unique_id "asVFWW-XhNO8ehusWsp0ugAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-06 18:55:15
(2 days ago)
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.42.208.135 - - \[06/Oct/2026:20:54:55 +0200\] "GET /.git/config HTTP/1.1" 307 5588 "-" "-"
...
show less
Bad Web Bot
Web App Attack
π³π±
ipoac.nl
2026-10-06 18:51:59
(2 days ago)
ipoac.nl:443 34.42.208.135 - - [06/Oct/2026:20:51:58 +0200] sip.ipoac.nl "GET /.git/config HTTP/1.1" ...
show more
ipoac.nl:443 34.42.208.135 - - [06/Oct/2026:20:51:58 +0200] sip.ipoac.nl "GET /.git/config HTTP/1.1" 403 6350 "-" "-"
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-10-06 18:45:38
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:45:35.728820 2026] [security2:error] [pid 18176:tid 18176] [client 34.42.208.135:50626] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "sio-org.cescfoundation.org"] [uri "/.git/config"] [unique_id "asVBz1ifL-ZbKh_rKr2AGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-10-06 18:44:01
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sinus.budyn.ovh | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 18:29:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:29:24.606779 2026] [security2:error] [pid 20302:tid 20302] [client 34.42.208.135:52214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "singapore-airshow.christinepeat.com"] [uri "/.git/config"] [unique_id "asU-BPFK4VDOH5pLg-4kSAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
Starburst SysOp Team
2026-10-06 18:21:08
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-sin2-2)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 18:10:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.42.208.135 (135.208.42.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:10:03.145279 2026] [security2:error] [pid 3026:tid 3026] [client 34.42.208.135:53614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "simplybrandedllc.com"] [uri "/.git/config"] [unique_id "asU5eym4L9-IBXh287pgtAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
FreeMyIP
2026-10-06 18:06:20
(2 days ago)
Automated fail2ban report: web application attack / scanning for exploitable paths.
Bad Web Bot
Web App Attack