๐บ๐ธ
TPI-Abuse
2026-09-21 18:41:14
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:41:09.166018 2026] [security2:error] [pid 9257:tid 9257] [client 34.87.6.41:50582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whiteweddingnapkins.com"] [uri "/.git/config"] [unique_id "arF6RSysr952JXA8V8k3SwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-21 18:02:07
(54 minutes ago)
Accessed trap at '/.git/config'
Web App Attack
๐จ๐ญ
4server
2026-09-21 17:29:49
(1 hour ago)
[MonSep2119:29:42.3423202026][security2:error][pid2174227:tid2174301][client34.87.6.41:0]ModSecurity ...
show more
[MonSep2119:29:42.3423202026][security2:error][pid2174227:tid2174301][client34.87.6.41:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"xn--sanierung-alter-huser-m2b.ch\"][uri\"/.git/config\"][unique_id\"arFphhZ4gOFq1JdRZ0tlpAAAAIw\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
iNetWorker
2026-09-21 17:04:58
(1 hour ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:42:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:41:53.865836 2026] [security2:error] [pid 4652:tid 4652] [client 34.87.6.41:35698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewhist.org"] [uri "/.git/config"] [unique_id "arFeUaMUIkmgoEY2KlUQYgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-21 16:40:13
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-mnz6-1)
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-21 16:28:50
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ssh.astropot.website | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
TechnoSolutions CL
2026-09-21 15:46:19
(3 hours ago)
34.87.6.41 - - [21/Sep/2026:15:46:18 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "-"
34.87.6.41 - - ...
show more
34.87.6.41 - - [21/Sep/2026:15:46:18 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "-"
34.87.6.41 - - [21/Sep/2026:15:46:19 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "-"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:31:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:31:00.341258 2026] [security2:error] [pid 19681:tid 19706] [client 34.87.6.41:43968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wheezer.org"] [uri "/.git/config"] [unique_id "arFNtMB2oIlJfrJRsQtb0QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-21 14:43:57
(4 hours ago)
cloudlinux2 fail2ban: 2026-09-21 16:38:58,810 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 16:38:58,810 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.12.147.81 - 2026-09-21 16:38:58cloudlinux2 fail2ban: 2026-09-21 16:38:53,718 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.12.147.81 - 2026-09-21 16:38:53cloudlinux2 fail2ban: 2026-09-21 16:39:40,283 fail2ban.filter [1598]: INFO [recidive] Found 104.28.212.209 - 2026-09-21 16:39:40cloudlinux2 fail2ban: 2026-09-21 16:39:40,282 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 104.28.212.209cloudlinux2 fail2ban: 2026-09-21 16:39:40,119 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 104.28.212.209 - 2026-09-21 16:39:40cloudlinux2 fail2ban: 2026-09-21 16:41:10,318 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.87.6.41 - 2026-09-21 16:41:10cloudlinux2 fail2ban: 2026-09-21 16:41:20,943 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.79.33.90 - 2026-09-21 16:41:20cloudlinux2 fail2ban: 2026-09-21
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 13:55:51
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:55:45.862486 2026] [security2:error] [pid 221965:tid 221965] [client 34.87.6.41:42586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stortfordmedical.com"] [uri "/.git/config"] [unique_id "arE3YRmBP4vFiYAsJbdPtgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-21 13:53:22
(5 hours ago)
CMS/framework probe: 34.87.6.41 - - [21/Sep/2026:15:53:21 +0200] "GET /.git/config HTTP/1.1" 444 0 " ...
show more
CMS/framework probe: 34.87.6.41 - - [21/Sep/2026:15:53:21 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36" asn=396982 org="Google LLC" country=SG
...
show less
Web App Attack
Anonymous
2026-09-21 13:00:27
(5 hours ago)
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CR ...
show more
Web probing (1 hits in 24h) on default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 12:06:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:06:40.410289 2026] [security2:error] [pid 11287:tid 11287] [client 34.87.6.41:36592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stablechase.com"] [uri "/.git/config"] [unique_id "arEd0FaTcmeCLnjr-wROygAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 11:17:53
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.6.41 (41.6.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 07:17:47.809061 2026] [security2:error] [pid 8847:tid 8847] [client 34.87.6.41:36380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wandathelittlestwizard.com"] [uri "/.git/config"] [unique_id "arESWxTUnKu8snOgoKP8OAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack