🇫🇷
masterguru
2026-09-08 08:13:51
(14 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:15:48
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:15:44.470003 2026] [security2:error] [pid 9331:tid 9331] [client 34.88.242.252:38544] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twilighthackers.com"] [uri "/.git/config"] [unique_id "ap994BHLR5PeffqiigjODAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pltcldvlpr
2026-09-08 00:05:33
(22 hours ago)
CMS/framework probe: 34.88.242.252 - - [08/Sep/2026:02:05:32 +0200] "GET /.git/config HTTP/1.1" 404 ...
show more
CMS/framework probe: 34.88.242.252 - - [08/Sep/2026:02:05:32 +0200] "GET /.git/config HTTP/1.1" 404 1499 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=FI
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:45:50
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:45:45.120878 2026] [security2:error] [pid 6528:tid 6528] [client 34.88.242.252:59810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twentytwocreative.net"] [uri "/.git/config"] [unique_id "ap9MqSj0PnKqtlJW2fennQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-07 22:28:26
(1 day ago)
(modsecurity) srv101 ModSecurity 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 30 in the l ...
show more
(modsecurity) srv101 ModSecurity 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 22:03:39
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇳🇱
Site.eu
2026-09-07 21:07:28
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 20:19:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:18:58.754149 2026] [security2:error] [pid 9877:tid 9877] [client 34.88.242.252:60706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twccsolutions.com"] [uri "/.git/config"] [unique_id "ap8cMmyKTVJg2mahQ8y3awAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 19:49:15
(1 day ago)
34.88.242.252 - - [07/Sep/2026:21:49:10 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 ...
show more
34.88.242.252 - - [07/Sep/2026:21:49:10 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.242.252 - - [07/Sep/2026:21:49:10 +0200] "GET /.env HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.242.252 - - [07/Sep/2026:21:49:11 +0200] "GET /.env.local HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.242.252 - - [07/Sep/2026:21:49:11 +0200] "GET /.env.production HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.242.252 - - [07/Sep/2026:21:49:11 +0200] "GET /.env.staging HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:33:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:33:52.012517 2026] [security2:error] [pid 26212:tid 26212] [client 34.88.242.252:55408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "twangcaster.com"] [uri "/.git/config"] [unique_id "ap8RoIPn-bykrppNoyCJQwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 18:17:50
(1 day ago)
Trying to access config files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:28:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:28:06.924658 2026] [security2:error] [pid 27733:tid 27733] [client 34.88.242.252:33620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvsolar.aguasolar.com"] [uri "/.git/config"] [unique_id "ap7J9iih_sXGf_Nf1veiHwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 14:21:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 13:00:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:00:03.053771 2026] [security2:error] [pid 30517:tid 30517] [client 34.88.242.252:51578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvr77.garyrankin.com"] [uri "/.git/config"] [unique_id "ap61UzGK11xKD1xZiZc1zgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:37:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.242.252 (252.242.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:36:58.374155 2026] [security2:error] [pid 19637:tid 19662] [client 34.88.242.252:60456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tvpin.com"] [uri "/.git/config"] [unique_id "ap6v6pX4BWrg1_e6ps3yEAAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack