๐ง๐ช
cmbplf
2026-09-24 11:50:56
(5 days ago)
333 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฉ๐ช
enjoyably
2026-09-24 07:26:56
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 05:45:35
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:45:29.273184 2026] [security2:error] [pid 26712:tid 26712] [client 34.93.117.144:51208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cxenterprise.com"] [uri "/.git/config"] [unique_id "arS4-e6iJaFc4k9BG2AU6AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:16:30
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:16:23.732796 2026] [security2:error] [pid 27550:tid 27550] [client 34.93.117.144:48426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpking.com"] [uri "/wordpress/.git/config"] [unique_id "arSkF32sThvVGpITRl3p_gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:36:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:36:06.807894 2026] [security2:error] [pid 31749:tid 31749] [client 34.93.117.144:49792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.adamsclothiers.com"] [uri "/wordpress/.git/config"] [unique_id "arR-hkT4UzuSwe4EU2naMQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-24 01:18:54
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 34.93.117.144 (IN/India/144.117.93.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.93.117.144 (IN/India/144.117.93.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:30:16
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:30:10.587003 2026] [security2:error] [pid 8961:tid 8961] [client 34.93.117.144:51780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comfortcartel.bilund.com"] [uri "/public/.git/config"] [unique_id "arRS8vhcLrH6M0XhQPNnVQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 20:26:15
(6 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 15:09:13
(6 days ago)
[ti-24al] Web exploit scanning: 19 suspicious requests detected by fail2ban jail apache-scanner. Exa ...
show more
[ti-24al] Web exploit scanning: 19 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /public/.git/config HTTP/1.1" 301 6376 "-" "crusader-worker/1.0"
34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /www/.git/config HTTP/1.1" 301 6370 "-" "crusader-worker/1.0"
34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /htdocs/.git/config HTTP/1.1" 301 6376 "-" "crusader-worker/1.0"
34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /src/.git/config HTTP/1.1" 301 6370 "-" "crusader-worker/1.0"
34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /backend/.git/config HTTP/1.1" 403 6369 "-" "crusader-worker/1.0"
34.93.117.144 - - [23/Sep/2026:17:09:10 +0200] "GET /app/.git/config HTTP/1.1" 301 6370
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 15:01:52
(6 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
Inartis
2026-09-23 13:15:24
(6 days ago)
34.93.117.144 - - [23/Sep/2026:15:15:23 +0200] "GET /.git/config HTTP/1.1" 302 415 "-" "crusader-wor ...
show more
34.93.117.144 - - [23/Sep/2026:15:15:23 +0200] "GET /.git/config HTTP/1.1" 302 415 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 11:20:04
(6 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 10:09:54
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 06:24:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.117.144 (144.117.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 02:24:10.260416 2026] [security2:error] [pid 14934:tid 15021] [client 34.93.117.144:44800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.destination-kitchen.com"] [uri "/app/.git/config"] [unique_id "arNwiovIZmYJFT249QBVXwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 05:01:21
(1 week ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /html/.git/config (+11 more) | 2026-09-23 05:01 UTC
show less
Hacking
Web App Attack