🇺🇸
TPI-Abuse
2026-09-05 02:34:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:34:05.860018 2026] [security2:error] [pid 18238:tid 18238] [client 34.96.234.251:59800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.whatyouhear.com"] [uri "/public/.git/config"] [unique_id "apt_nWWG-uN5OtqlQOqPbAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-05 01:24:59
(4 hours ago)
2026/09/05 01:24:58 [error] 1171583#1171583: *557693134 access forbidden by rule, client: 34.96.234. ...
show more
2026/09/05 01:24:58 [error] 1171583#1171583: *557693134 access forbidden by rule, client: 34.96.234.251, server: fn.binixo.es, request: "GET /src/.git/config HTTP/1.1", host: "li1822-160.members.linode.com"
2026/09/05 01:24:58 [error] 1171583#1171583: *557693135 access forbidden by rule, client: 34.96.234.251, server: fn.binixo.es, request: "GET /site/.git/config HTTP/1.1", host: "li1822-160.members.linode.com"
2026/09/05 01:24:58 [error] 1171583#1171583: *557693136 access forbidden by rule, client: 34.96.234.251, server: fn.binixo.es, request: "GET /htdocs/.git/config HTTP/1.1", host: "li1822-160.members.linode.com"
...
show less
Web App Attack
Anonymous
2026-09-04 22:20:02
(7 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
e.fierstra
2026-09-04 21:50:53
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:38:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:38:36.600316 2026] [security2:error] [pid 3099:tid 3099] [client 34.96.234.251:34752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dividivipartners.com"] [uri "/www/.git/config"] [unique_id "aps6XBTaf_7oyM3MoZ0WbQAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-04 20:48:45
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-stl2-13)
Hacking
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 19:15:00
(10 hours ago)
[04/Sep/2026:22:15:00 +0300] -- 34.96.234.251 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[04/Sep/2026:22:15:00 +0300] -- 34.96.234.251 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇩🇪
iNetWorker
2026-09-04 11:03:23
(18 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇫🇷
dynamix
2026-09-04 07:02:20
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:21:21
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:21:14.505066 2026] [security2:error] [pid 19571:tid 19615] [client 34.96.234.251:38672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.arthansl.com"] [uri "/public/.git/config"] [unique_id "appjWuzmEVCygGThsAdu-wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:36:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.234.251 (251.234.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:36:09.814433 2026] [security2:error] [pid 12222:tid 12222] [client 34.96.234.251:55078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.robtown.com"] [uri "/api/.git/config"] [unique_id "apo8qb23dRoXBDSnNcRCKQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-04 00:32:17
(1 day ago)
[REDACTED] 34.96.234.251 - - [04/Sep/2026:02:32:16 +0200] "GET /src/.git/config HTTP/1.1" 404 4471 " ...
show more
[REDACTED] 34.96.234.251 - - [04/Sep/2026:02:32:16 +0200] "GET /src/.git/config HTTP/1.1" 404 4471 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇫🇮
paissangroup
2026-09-04 00:31:55
(1 day ago)
Multiple WAF Violations
Web App Attack
🇬🇧
consul.to
2026-09-04 00:29:49
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇦🇺
aranguren.org
2026-09-03 23:27:07
(1 day ago)
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /app/.git/config HTTP/1.1" 404 999 "-" "crusader ...
show more
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /app/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /wordpress/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /var/www/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /site/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /public/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
34.96.234.251 - - [04/Sep/2026:09:27:06 +1000] "GET /src/.git/config HTTP/1.1" 404 999 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot