🇺🇸
TPI-Abuse
2026-09-04 07:26:26
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:26:18.289240 2026] [security2:error] [pid 22609:tid 22609] [client 34.97.32.114:39246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thomaschemicals.com"] [uri "/.git/config"] [unique_id "appymvjlRsYqkMsq83MksAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:43:28
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:43:22.833945 2026] [security2:error] [pid 18035:tid 18035] [client 34.97.32.114:39954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "imjustsayin.yeswedeliver.org"] [uri "/api/.git/config"] [unique_id "appoinWPpsI0nEaCTF6sUAAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
webanyone
2026-09-04 05:32:05
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇳🇱
Savvii
2026-09-04 04:32:52
(3 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:14:12
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:14:06.416848 2026] [security2:error] [pid 5487:tid 5487] [client 34.97.32.114:59718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.webuydinwiddiehouses.com"] [uri "/backend/.git/config"] [unique_id "appFjgoJFxy1XXCa5R9rvQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:31:05
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:30:59.559952 2026] [security2:error] [pid 26544:tid 26544] [client 34.97.32.114:36176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "albertmassaad.com.easternimport.com"] [uri "/www/.git/config"] [unique_id "apofU0ypuMKk9GBcJ4q2dwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
aranguren.org
2026-09-04 01:05:49
(6 hours ago)
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /html/.git/config HTTP/1.1" 404 998 "-" "crusader ...
show more
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /html/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /src/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /backend/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /wordpress/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /var/www/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
34.97.32.114 - - [04/Sep/2026:11:05:49 +1000] "GET /public/.git/config HTTP/1.1" 404 998 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Anonymous
2026-09-03 23:42:58
(7 hours ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/var/www/.git/config | /api/ ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/var/www/.git/config | /api/.git/config | /.git/config
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 22:59:25
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 19:08:56
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:08:50.067660 2026] [security2:error] [pid 1363:tid 1363] [client 34.97.32.114:50150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "meltonspace.com"] [uri "/wordpress/.git/config"] [unique_id "apnFwlBzrAJqsIyQvWA5QwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 17:59:55
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 17:56:43
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:56:38.373957 2026] [security2:error] [pid 10924:tid 10924] [client 34.97.32.114:34482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "apsni.net"] [uri "/htdocs/.git/config"] [unique_id "apm01h7V9kMBwkee5jXBtQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-03 14:21:17
(17 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 14:00:47
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.32.114 (114.32.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:00:41.147939 2026] [security2:error] [pid 32453:tid 32453] [client 34.97.32.114:50002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tijuana-bibles.tijuanabible.org"] [uri "/api/.git/config"] [unique_id "apl9iSg1UHymrWE5P2JCMQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
YF
2026-09-03 11:00:11
(20 hours ago)
Git config exposure probe
Web App Attack