๐ฉ๐ช
on-com
2026-10-02 01:41:13
(11 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-10-02 01:39:17
(11 hours ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.91.254.140 (140.254.91.34.bc.googleuse ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.91.254.140 (140.254.91.34.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 01:38:43
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:38:40.284561 2026] [security2:error] [pid 20938:tid 20938] [client 34.91.254.140:57060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kirbysheetmetalworks.com"] [uri "/.git/config"] [unique_id "ar8LIJggphjJdp0ZRnOB1AAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 01:29:03
(11 hours ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ฌ๐ง
pinguin
2026-10-02 01:22:30
(11 hours ago)
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from NL.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 01:05:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 21:05:27.984902 2026] [security2:error] [pid 24881:tid 24881] [client 34.91.254.140:58880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingstoneproperties.sendalawyerletter.com"] [uri "/.git/config"] [unique_id "ar8DV1E2aavpfPGXqHLQhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 00:45:09
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:45:05.868141 2026] [security2:error] [pid 18970:tid 18970] [client 34.91.254.140:49958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdomvalleyfarm.com"] [uri "/.git/config"] [unique_id "ar7-kX80iA1-4ZyHbXmhMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-10-02 00:17:08
(12 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 00:16:12
(12 hours ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.91.254.140 - - [02/Oct/2026:02:15:52 +0200] "GET /.git/config HTTP/1.1" 404 7928 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-10-02 00:11:48
(12 hours ago)
Probing for .git:
34.91.254.140 - - [02/Oct/2026:02:11:46 +0200] "GET /.git/config HTTP/1.1" 400 230 ...
show more
Probing for .git:
34.91.254.140 - - [02/Oct/2026:02:11:46 +0200] "GET /.git/config HTTP/1.1" 400 230 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 00:02:11
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.254.140 (140.254.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 20:02:04.011687 2026] [security2:error] [pid 31444:tid 31444] [client 34.91.254.140:36898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kimmimorikawa.com"] [uri "/.git/config"] [unique_id "ar70fL7p4AMQSLyqbdBYLgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-01 23:43:02
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.91.254.140 (140.254.91.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.91.254.140 (140.254.91.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 23:41:28
(13 hours ago)
459 requests with url.path */.git/config
193 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
paissangroup
2026-10-01 23:26:25
(13 hours ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-01 23:19:04
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack