🇫🇷
masterguru
2026-09-06 03:45:26
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-06 00:42:26
(4 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇿
Antinson
2026-09-05 08:21:26
(21 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-05 01:20:45
(1 day ago)
34.97.133.156 - - [04/Sep/2026:19:20:44 -0600] "GET /api/.git/config HTTP/1.1" 300 8158 "-" "crusade ...
show more
34.97.133.156 - - [04/Sep/2026:19:20:44 -0600] "GET /api/.git/config HTTP/1.1" 300 8158 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:23:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:23:04.922607 2026] [security2:error] [pid 9018:tid 9018] [client 34.97.133.156:43950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.budpowellbio.com"] [uri "/src/.git/config"] [unique_id "aps2uK6A-1ikifqIJDSEEgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:10:50
(1 day ago)
Multiple WAF Violations
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 19:28:58
(1 day ago)
cloudlinux2 fail2ban: 2026-09-04 21:25:30,860 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-04 21:25:30,860 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 142.111.152.188 - 2026-09-04 21:25:30cloudlinux2 fail2ban: 2026-09-04 21:26:53,395 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.131.193.56 - 2026-09-04 21:26:52cloudlinux2 fail2ban: 2026-09-04 21:26:57,311 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.29 - 2026-09-04 21:26:56cloudlinux2 fail2ban: 2026-09-04 21:27:17,104 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.172.32.198 - 2026-09-04 21:27:16cloudlinux2 fail2ban: 2026-09-04 21:27:40,168 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.173.31.56cloudlinux2 fail2ban: 2026-09-04 21:27:47,895 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.213.13 - 2026-09-04 21:27:47cloudlinux2 fail2ban: 2026-09-04 21:28:13,240 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.97.133.156 - 2026-09-04 21:28:12cloudlinux2 fail2ban:
show less
Web App Attack
🇩🇪
LRob
2026-09-04 17:21:03
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /src/.git/config (+11 more) | 2026-09-04 17:21 UTC
show less
Hacking
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 16:28:05
(1 day ago)
34.97.133.156 - - [04/Sep/2026:12:28:05 -0400] "GET /html/.git/config HTTP/1.1" 403 5518 "-" "crusad ...
show more
34.97.133.156 - - [04/Sep/2026:12:28:05 -0400] "GET /html/.git/config HTTP/1.1" 403 5518 "-" "crusader-worker/1.0"
34.97.133.156 - - [04/Sep/2026:12:28:05 -0400] "GET /www/.git/config HTTP/1.1" 403 5518 "-" "crusader-worker/1.0"
34.97.133.156 - - [04/Sep/2026:12:28:05 -0400] "GET /app/.git/config HTTP/1.1" 403 5518 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-04 14:12:55
(1 day ago)
[da.kdns.gr] httpd-config-scan: sites=www.xamogelo.edu.gr; logs=/var/log/httpd/domains/xamogelo.edu. ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.xamogelo.edu.gr; logs=/var/log/httpd/domains/xamogelo.edu.gr.log; samples=/api/.git/config | /www/.git/config | /src/.git/config
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 13:05:46
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 08:46:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:46:20.111424 2026] [security2:error] [pid 2447673:tid 2447699] [client 34.97.133.156:54448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.layoverlocations.com"] [uri "/wordpress/.git/config"] [unique_id "apqFXGckBefvsU_zC6xglwAAAtM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:58:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:58:35.454626 2026] [security2:error] [pid 6260:tid 6260] [client 34.97.133.156:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bradleybarefoot.com"] [uri "/html/.git/config"] [unique_id "app6K9YBgQtsGGJw_i4O0wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 07:37:14
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:39:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.156 (156.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:39:07.546830 2026] [security2:error] [pid 17345:tid 17345] [client 34.97.133.156:58676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "female.bodybuildbid.com"] [uri "/src/.git/config"] [unique_id "apoTK4p0SAi2hwyyKoxC3AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack