Anonymous
2026-06-15 09:37:19
(1 hour ago)
34.87.9.220 - - [15/Jun/2026:11:37:18 +0200] "GET /backend/.git/config HTTP/1.1" 301 169 "-" "Mozill ...
show more
34.87.9.220 - - [15/Jun/2026:11:37:18 +0200] "GET /backend/.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/12.1.1 Safari/605.1.15"
show less
Web App Attack
๐บ๐ธ
cwytech
2026-06-15 06:29:08
(4 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:49:26
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:49:19.857865 2026] [security2:error] [pid 23753:tid 23753] [client 34.87.9.220:46336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dhsgrad.net"] [uri "/dashboard/.git/config"] [unique_id "ai-SX_h68kM6y7BQUytK7gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-06-15 04:56:42
(6 hours ago)
CMS/framework probe: 34.87.9.220 - - [15/Jun/2026:06:56:29 +0200] "GET /.git/config HTTP/1.1" 404 56 ...
show more
CMS/framework probe: 34.87.9.220 - - [15/Jun/2026:06:56:29 +0200] "GET /.git/config HTTP/1.1" 404 564 "-" "Mozilla/5.0 (X11; FreeBSD amd64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/35.0.1916.153 Safari/537.36" asn=396982 org="Google LLC" country=SG
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-06-15 04:25:53
(6 hours ago)
6.194 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 03:20:39
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:20:33.070441 2026] [security2:error] [pid 16666:tid 16666] [client 34.87.9.220:46896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amaia.biz"] [uri "/v1/.git/config"] [unique_id "ai9vgQ9Gu4AVcO07oT7IGQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-06-15 02:39:32
(8 hours ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 60 hits.
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 01:52:53
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
voormedia
2026-06-15 01:27:46
(9 hours ago)
Accessed trap at '/.git/config'
Web App Attack
๐จ๐ญ
backslash
2026-06-15 01:03:01
(9 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 00:58:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.9.220 (220.9.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:58:54.133053 2026] [security2:error] [pid 2173:tid 2173] [client 34.87.9.220:46464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wgs.cc"] [uri "/laravel/.git/config"] [unique_id "ai9OTnrfxVBcC48QN8mu7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-06-15 00:28:18
(10 hours ago)
Domain : grekalbed.it
Rule : config
2026-06-15 00:26:36 ***hidden-privacy*** GET /api/.git/config - ...
show more
Domain : grekalbed.it
Rule : config
2026-06-15 00:26:36 ***hidden-privacy*** GET /api/.git/config - 443 - 34.87.9.220 HTTP/1.1 Mozilla/5.0 (Windows; U; Windows NT 6.1; en-GB; rv:1.9.1.17) Gecko/20110123 (like Firefox/3.x) SeaMonkey/2.0.12 - www.grekalbed.it 404 8 0 313 247 378 - -
show less
Hacking
SQL Injection
๐บ๐ธ
mnsf
2026-06-15 00:12:10
(10 hours ago)
Too many Status 40X (30)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-14 23:42:59
(11 hours ago)
[MonJun1501:42:52.5010562026][security2:error][pid3338868:tid3338884][client34.87.9.220:0]ModSecurit ...
show more
[MonJun1501:42:52.5010562026][security2:error][pid3338868:tid3338884][client34.87.9.220:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"immobiliaretrentino.it\"][uri\"/app/.git/config\"][unique_id\"ai88fJ3wLQBVKk8VEJlPtgAAAQw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-06-14 23:10:00
(11 hours ago)
34.87.9.220 - - [14/Jun/2026:17:10:00 -0600] "GET /htdocs/.git/config HTTP/1.1" 404 11261 "-" "Mozil ...
show more
34.87.9.220 - - [14/Jun/2026:17:10:00 -0600] "GET /htdocs/.git/config HTTP/1.1" 404 11261 "-" "Mozilla/4.0 (PSP (PlayStation Portable); 2.00)"
...
show less
Web App Attack