🇺🇸
Charlesiv
2026-09-09 00:25:12
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
Timestamp: 2026-09-08T23:37:27Z
Ray ID: a381c7f84c3e7db2
UA: Empty string
show less
Bad Web Bot
Anonymous
2026-09-08 23:59:27
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:52:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:52:43.805121 2026] [security2:error] [pid 11931:tid 11931] [client 34.80.143.10:33140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astariafilms.com"] [uri "/.git/config"] [unique_id "aqCfy4zWCCv499XXLZXKuQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pltcldvlpr
2026-09-08 23:24:46
(1 day ago)
CMS/framework probe: 34.80.143.10 - - [09/Sep/2026:01:24:46 +0200] "GET /.git/config HTTP/1.1" 444 0 ...
show more
CMS/framework probe: 34.80.143.10 - - [09/Sep/2026:01:24:46 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "-" asn=396982 org="Google LLC" country=TW
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:15:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:14:57.277157 2026] [security2:error] [pid 12269:tid 12269] [client 34.80.143.10:33714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assets.kanata.ws"] [uri "/.git/config"] [unique_id "aqCW8c58tKDStTuwapi64AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇹
René Hickersberger
2026-09-08 23:13:11
(1 day ago)
malicious bot detected: violations="hit-honeypot"; user_agent=""
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:55:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:55:12.606788 2026] [security2:error] [pid 13771:tid 13771] [client 34.80.143.10:59788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assembliesofgodinsamoa.org.nomanszone.org"] [uri "/.git/config"] [unique_id "aqCSUNq7NPqAxU7FvlSHPQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 22:52:27
(1 day ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/config | 2026-09-08 22:52 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /.git/config | 2026-09-08 22:52 UTC
show less
Port Scan
Web App Attack
🇩🇪
Selckie
2026-09-08 22:39:42
(1 day ago)
fail2ban: NGINX unusual impact
Web App Attack
Anonymous
2026-09-08 22:35:02
(1 day ago)
Trying to access config files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:29:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:29:00.468475 2026] [security2:error] [pid 17599:tid 17599] [client 34.80.143.10:58306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asmechatronics.nextngnr.com"] [uri "/.git/config"] [unique_id "aqCMLFdPFLRGafUMCLJs_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:13:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:13:41.041899 2026] [security2:error] [pid 27729:tid 27729] [client 34.80.143.10:34820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ask2023.com.whatifandwhynot.xyz"] [uri "/.git/config"] [unique_id "aqCIleY7fGBGzFIawAhtnQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:58:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:58:02.465346 2026] [security2:error] [pid 12604:tid 12604] [client 34.80.143.10:39062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asian-aerospace.christinepeat.com"] [uri "/.git/config"] [unique_id "aqCE6lRWgILtBxjVJ2DNIAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇹
NotACaptcha
2026-09-08 21:51:34
(1 day ago)
webserver:443 [09/Sep/2026] "GET /.git/config HTTP/1.1" 403 5692
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:42:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.143.10 (10.143.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:42:37.058195 2026] [security2:error] [pid 24568:tid 24568] [client 34.80.143.10:52742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ashleycroft.com"] [uri "/.git/config"] [unique_id "aqCBTW4D4-R9_l0oOAeZjwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack