🇩🇪
Zentro
2026-09-07 04:29:15
(13 hours ago)
Automated honeypot/fail2ban detection
Port Scan
Hacking
Web App Attack
🇺🇸
Charlesiv
2026-09-07 04:00:18
(14 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-07T03:10:56Z
Ray ID: a37285f43d75dac7
UA: Mozilla/5.0 (X11; Linux x86_64)
show less
Bad Web Bot
🇩🇪
ghostwarriors
2026-09-07 03:20:11
(14 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
Aurealize
2026-09-07 03:16:24
(14 hours ago)
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.git/con ...
show more
Automated Sensitive File discovery attempt detected by a Cloudflare WAF custom rule. Path: /.git/config.
show less
Web App Attack
Hacking
🇺🇸
whatda
2026-09-07 03:11:47
(14 hours ago)
HTTP tarpit triggered at /.git/config. Scanner trapped for ~30s. UA: Mozilla/5.0 (X11; Linux x86_64)
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 03:07:05
(14 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-07 02:26:31.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:06:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.118.81 (81.118.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.118.81 (81.118.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:06:49.733275 2026] [security2:error] [pid 12896:tid 12896] [client 34.6.118.81:42772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "herstonfarm.com"] [uri "/.git/config"] [unique_id "ap4qSd_3kZu27DAdf5RKTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 03:06:48
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇳🇴
jad-abuse
2026-09-07 03:05:14
(14 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
Anonymous
2026-09-07 03:02:03
(15 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇩🇪
yitzhaq
2026-09-07 02:56:45
(15 hours ago)
34.6.118.81 - - [07/Sep/2026:04:38:18 +0200] "GET /.git/config HTTP/1.1" 403 4403 "-" "Mozilla/5.0 ( ...
show more
34.6.118.81 - - [07/Sep/2026:04:38:18 +0200] "GET /.git/config HTTP/1.1" 403 4403 "-" "Mozilla/5.0 (X11; Linux x86_64)"
34.6.118.81 - - [07/Sep/2026:04:56:04 +0200] "GET /.git/config HTTP/1.1" 403 4532 "-" "Mozilla/5.0 (X11; Linux x86_64)"
34.6.118.81 - - [07/Sep/2026:04:56:42 +0200] "GET /.git/config HTTP/1.1" 403 4441 "-" "Mozilla/5.0 (X11; Linux x86_64)"
show less
Web App Attack
Hacking
🇬🇧
gurnip
2026-09-07 02:56:23
(15 hours ago)
Vulnerability probe of page /.git/config, not found on server.
Brute-Force
Web App Attack
🇩🇪
pltcldvlpr
2026-09-07 02:53:53
(15 hours ago)
CMS/framework probe: 34.6.118.81 - - [07/Sep/2026:04:53:52 +0200] "GET /.git/config HTTP/1.1" 444 0 ...
show more
CMS/framework probe: 34.6.118.81 - - [07/Sep/2026:04:53:52 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64)" asn=396982 org="Google LLC" country=NL
...
show less
Web App Attack
🇩🇪
kkw
2026-09-07 02:53:17
(15 hours ago)
[REDACTED] 34.6.118.81 - - [07/Sep/2026:04:53:16 +0200] "GET /.git/config HTTP/1.1" 404 4500 "-" "Mo ...
show more
[REDACTED] 34.6.118.81 - - [07/Sep/2026:04:53:16 +0200] "GET /.git/config HTTP/1.1" 404 4500 "-" "Mozilla/5.0 (X11; Linux x86_64)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:51:48
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.6.118.81 (81.118.6.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.6.118.81 (81.118.6.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:51:40.116179 2026] [security2:error] [pid 16789:tid 16789] [client 34.6.118.81:38206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "godscreationobservatory.com"] [uri "/.git/config"] [unique_id "ap4mvP_ZhCBxH7OnvN9aPQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack