Anonymous
2026-09-10 21:10:14
(6 hours ago)
"GET /.git/config HTTP/1.1"
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-10 18:58:36
(9 hours ago)
721 requests with url.path */.git/config
248 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇬🇧
foxxelabs
2026-09-10 17:54:07
(10 hours ago)
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Kn ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Known exploit path: /.git/config | User-Agent: none
show less
Web App Attack
🇵🇱
Budyn
2026-09-10 17:26:57
(10 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: beszel.budyn.wtf | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-10 17:10:23
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-10 17:06:39
(10 hours ago)
Abuse Detected (16)
Brute-Force
Web App Attack
Anonymous
2026-09-10 16:57:18
(11 hours ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 16:46:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:46:30.852918 2026] [security2:error] [pid 19318:tid 19318] [client 34.66.86.177:52304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bestnebraskadetective.com"] [uri "/.git/config"] [unique_id "aqLe5rk6xChnIve1JPieMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-10 15:43:58
(12 hours ago)
cloudlinux2 fail2ban: 2026-09-10 17:39:14,456 fail2ban.filter [1892]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-10 17:39:14,456 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 173.239.211.90 - 2026-09-10 17:39:13cloudlinux2 fail2ban: 2026-09-10 17:39:35,445 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.125.245.239 - 2026-09-10 17:39:35cloudlinux2 fail2ban: 2026-09-10 17:39:35,950 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.125.245.239 - 2026-09-10 17:39:35cloudlinux2 fail2ban: 2026-09-10 17:40:16,850 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 92.119.36.17 - 2026-09-10 17:40:16cloudlinux2 fail2ban: 2026-09-10 17:40:16,634 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 92.119.36.37 - 2026-09-10 17:40:16cloudlinux2 fail2ban: 2026-09-10 17:40:17,898 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 92.119.36.2 - 2026-09-10 17:40:17cloudlinux2 fail2ban: 2026-09-10 17:40:51,407 fail2ban.filter [1892]: INFO [plesk-proftpd] Found 217.160.254.206 - 2026-09-10 17:40:51cloudl
show less
FTP Brute-Force
Web App Attack
🇳🇱
JaRoNL
2026-09-10 15:43:57
(12 hours ago)
34.66.86.177 - - [10/Sep/2026:17:43:56 +0200] "GET /.git/config HTTP/1.1" 404 7784 "-" "-"
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:41:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:41:35.038531 2026] [security2:error] [pid 4048239:tid 4048253] [client 34.66.86.177:55384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "besfixedwireless.com.exede-sales.com"] [uri "/.git/config"] [unique_id "aqLPr2iogwLUv1jrcqCPiQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:26:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:26:31.848166 2026] [security2:error] [pid 30476:tid 30476] [client 34.66.86.177:50968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "berntson.org"] [uri "/.git/config"] [unique_id "aqLMJ5nZP0-0bJm7VT4bdAAAAFs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 15:25:02
(12 hours ago)
suspicious request in access.log
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-10 15:18:42
(12 hours ago)
[Fri Sep 11 01:18:42.124119 2026] [security2:error] [pid 489564] [client 34.66.86.177:49208] [client ...
show more
[Fri Sep 11 01:18:42.124119 2026] [security2:error] [pid 489564] [client 34.66.86.177:49208] [client 34.66.86.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "bermanfamily.com.au"] [uri "/.git/config"] [unique_id "aqLKUvegRRhkrRns_qB7EAAAAAo"]
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:10:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.86.177 (177.86.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:10:21.540826 2026] [security2:error] [pid 15883:tid 15883] [client 34.66.86.177:38942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "berklie.com"] [uri "/.git/config"] [unique_id "aqLIXb908jpO2SXguLZ44AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack