๐ง๐ช
cmbplf
2026-06-15 12:43:04
(3 hours ago)
738 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 09:26:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:26:20.633549 2026] [security2:error] [pid 3558:tid 3558] [client 34.64.228.157:45290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iostation.com"] [uri "/backend/.git/config"] [unique_id "ai_FPNgV9EsWiUI2gQme6AAAAGo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
sernate
2026-06-15 08:46:05
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (KR/South Korea/157.228.64.34.bc. ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (KR/South Korea/157.228.64.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
Anonymous
2026-06-15 08:38:45
(7 hours ago)
PSCSERV WPSCAN 34.64.228.157
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-15 05:32:08
(10 hours ago)
Web scanning / probing for vulnerable paths | URL: /.git/config | Evidence: www.viajesxamoni.es 34.6 ...
show more
Web scanning / probing for vulnerable paths | URL: /.git/config | Evidence: www.viajesxamoni.es 34.64.228.157 - - [15/Jun/2026:07:31:37 +0200] \"GET /.git/config HTTP/1.1\" 404 4162 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36\" GEOIP_COUNTRY_CODE=KR | ASN: GOOGLE-CLOUD-PLATFORM | Country: KR
show less
Port Scan
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-15 03:35:20
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
big-cloud.nl
2026-06-15 03:26:41
(12 hours ago)
Try to access /frontend/.git/config
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-15 03:20:07
(12 hours ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/4.0 (compatible; MSIE 6.0; Windows CE; IEMobile 7.11)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:03:30
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:03:24.454054 2026] [security2:error] [pid 884:tid 884] [client 34.64.228.157:39110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.trclegacyholdings.org.ryanc.net"] [uri "/src/.git/config"] [unique_id "ai9rfNYOLeviwR77jkfT8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 02:30:46
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐จ๐ญ
Origon
2026-06-15 02:28:17
(13 hours ago)
http-sensitive-files - IP: 34.64.228.157 - time="2026-06-15T04:28:16+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.64.228.157 - time="2026-06-15T04:28:16+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.64.228.157 (KR/396982) : 4h ban on Ip 34.64.228.157" module=db
show less
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-15 00:05:09
(15 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:46:50
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:46:44.909823 2026] [security2:error] [pid 16964:tid 16964] [client 34.64.228.157:47950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.apuntesdeinversion.com.visionremota.info"] [uri "/build/.git/config"] [unique_id "ai89ZKuPrdmI-L85ADwXnAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:40:09
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:40:03.008271 2026] [security2:error] [pid 21446:tid 21446] [client 34.64.228.157:60874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightupaustralia.com"] [uri "/.git/config"] [unique_id "ai8twxoqzMtoIDgXKKErGgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:09:27
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.228.157 (157.228.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:09:19.962664 2026] [security2:error] [pid 17353:tid 17353] [client 34.64.228.157:41426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fabulouswire.net"] [uri "/app/.git/config"] [unique_id "ai8mjxCEPyYKZd_lALS2SAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack