🇺🇸
TPI-Abuse
2026-09-03 16:46:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:46:31.811736 2026] [security2:error] [pid 20932:tid 20932] [client 34.65.209.236:44024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rxrepconnect.circlehealthcaregroup.com"] [uri "/wordpress/.git/config"] [unique_id "apmkZxR6q-44ZevZhQbDfgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 15:36:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:36:14.185209 2026] [security2:error] [pid 3475:tid 3475] [client 34.65.209.236:57214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "impressionista.net"] [uri "/www/.git/config"] [unique_id "apmT7kZyd0uu9ox8inLNEwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-03 15:30:45
(1 day ago)
Repeated exploit attempts, for example: /site/.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:05:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:04:56.868574 2026] [security2:error] [pid 11713:tid 11713] [client 34.65.209.236:45704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starrmail.net"] [uri "/app/.git/config"] [unique_id "aplweCXful7ahFn-8HO1KgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇪
AutosOnShow
2026-09-03 10:54:06
(1 day ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-03 10:53:06.121 |
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 10:35:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
e.fierstra
2026-09-03 10:27:33
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-03 09:55:08
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-03 09:30:14
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.65.209.236 (CH/Switzerland/236.209.65.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.209.236 (CH/Switzerland/236.209.65.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 06:23:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.209.236 (236.209.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:23:30.598612 2026] [security2:error] [pid 21189:tid 21189] [client 34.65.209.236:60858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apexhumanoidrobots.com"] [uri "/site/.git/config"] [unique_id "apkSYnkTpbVDFmv9_aQvqgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:08:47
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.65.209.236 (236.209.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.209.236 (236.209.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:08:42.002784 2026] [security2:error] [pid 29444:tid 29444] [client 34.65.209.236:57322] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pathpointsandbox.click"] [uri "/html/.git/config"] [unique_id "apkA2mZvVL2uM97PPkorOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack