๐ณ๐ฑ
Site.eu
2026-09-29 15:49:26
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-29 07:12:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:12:27.802762 2026] [security2:error] [pid 28384:tid 28384] [client 34.50.66.109:44708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.susannahtuttle.com.player-care.com"] [uri "/.git/config"] [unique_id "artk216H8PLc0Fr6dXJGcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 10:21:16
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:21:13.296826 2026] [security2:error] [pid 25936:tid 25958] [client 34.50.66.109:51896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stupidlikeyou.ceol.us"] [uri "/.git/config"] [unique_id "aro_mTFsjzLdzUg06OIbTQAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
strefapi_com
2026-09-28 05:50:35
(4 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 02:13:48
(5 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-27 00:29:33
(6 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config (+6 more) | 2026-09-27 00:29 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 21:17:12
(6 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:36:40
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:36:24.358840 2026] [security2:error] [pid 21585:tid 21585] [client 34.50.66.109:41420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kevinfranz.com"] [uri "/.git/config"] [unique_id "argsyIuSEFVf2WuzPRZDRAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 17:10:22
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 13:10:15.351235 2026] [security2:error] [pid 26463:tid 26463] [client 34.50.66.109:51848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bryjer.com"] [uri "/.git/config"] [unique_id "arf8d78sDJZgTueYz6eBkQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:15:10
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:15:02.686827 2026] [security2:error] [pid 16033:tid 16096] [client 34.50.66.109:57356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.aliqsha.com"] [uri "/.git/config"] [unique_id "arfhdnnvAO6HW0YS2WNhzwAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-26 09:34:01
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-25 10:18:32
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ฆ๐บ
paulshipley.com.au
2026-09-25 00:39:45
(1 week ago)
[Fri Sep 25 10:39:45.022724 2026] [security2:error] [pid 595692] [client 34.50.66.109:49436] [client ...
show more
[Fri Sep 25 10:39:45.022724 2026] [security2:error] [pid 595692] [client 34.50.66.109:49436] [client 34.50.66.109] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "shotbysuzanne.com.au"] [uri "/.git/config"] [unique_id "arXC0dQINElJUsKXZHV3rwAAAAI"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:13:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.66.109 (109.66.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:12:59.949564 2026] [security2:error] [pid 24055:tid 24055] [client 34.50.66.109:33788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.srosa.danged.com"] [uri "/.git/config"] [unique_id "arTbiyka354rHTLnc4ycCgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 12:24:15
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking