Anonymous
2026-09-15 18:05:02
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:59:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:59:45.921768 2026] [security2:error] [pid 1430:tid 1430] [client 34.80.197.25:39864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nbcnewsradio.com"] [uri "/.git/config"] [unique_id "aqmHkX99R6py4GknC5lWcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:42:02
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:41:54.003205 2026] [security2:error] [pid 30229:tid 30229] [client 34.80.197.25:57146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "navarreunited.nysasports.com"] [uri "/.git/config"] [unique_id "aqmDYkAL-YpfBu20OnBiEgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
joharikop
2026-09-15 17:36:30
(1 hour ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:24:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:23:55.840914 2026] [security2:error] [pid 14100:tid 14100] [client 34.80.197.25:45734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturalacu.com"] [uri "/.git/config"] [unique_id "aql_K-zqv0uvnvHuM-i6-gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-15 17:08:44
(2 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:03:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:03:30.700203 2026] [security2:error] [pid 32252:tid 32252] [client 34.80.197.25:47714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nataliedenizescott.com"] [uri "/.git/config"] [unique_id "aql6Ykxu-N5BW69kyp83RAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-15 16:46:23
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇮🇩
Burayot
2026-09-15 16:45:11
(2 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.80.197.25 (TW/Taiwan/25.197.80.3 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.80.197.25 (TW/Taiwan/25.197.80.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-15 16:26:31
(2 hours ago)
34.80.197.25 - - [15/Sep/2026:16:26:30 +0000] "GET /.git/config HTTP/1.1" 404 11758 "-" "-"
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:24:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:24:22.643668 2026] [security2:error] [pid 28062:tid 28062] [client 34.80.197.25:56156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naomipyle.com.joshuashands.org"] [uri "/.git/config"] [unique_id "aqlxNnzd70RvAXcBMmZLxgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 16:07:03
(3 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-15 15:26:34.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 16:01:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.197.25 (25.197.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:01:24.752908 2026] [security2:error] [pid 12487:tid 12487] [client 34.80.197.25:54416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naked60yearoldgaymen.com"] [uri "/.git/config"] [unique_id "aqlr1F1_a8vLA0npOGeVfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-15 15:57:08
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 15:53:47
(3 hours ago)
34.80.197.25 - - [15/Sep/2026:17:53:47 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "-"
Web App Attack