Anonymous
2026-08-17 19:05:03
(3 minutes ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
NerdyMcNerderson
2026-08-17 19:02:21
(6 minutes ago)
MarekCloud auto-ban: Git exposure probe: GET /.git/config
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-08-17 19:02:00
(6 minutes ago)
[Tue Aug 18 05:01:59.461228 2026] [security2:error] [pid 137295] [client 35.190.166.21:37462] [clien ...
show more
[Tue Aug 18 05:01:59.461228 2026] [security2:error] [pid 137295] [client 35.190.166.21:37462] [client 35.190.166.21] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/.git/config"] [unique_id "aoNap_JLu4HNOPNORDWYNgAAABY"]
...
show less
Web App Attack
๐ฉ๐ช
Marc
2026-08-17 18:57:14
(11 minutes ago)
35.190.166.21 - - [17/Aug/2026:20:57:12 +0200] "GET /.git/config HTTP/1.1" 404 4620 "-" "-" 35.190.1 ...
show more
35.190.166.21 - - [17/Aug/2026:20:57:12 +0200] "GET /.git/config HTTP/1.1" 404 4620 "-" "-" 35.190.166.21 - - [17/Aug/2026:20:57:13 +0200] "GET /.git/config HTTP/1.1" 404 4621 "-" "-" 35.190.166.21 - - [17/Aug/2026:20:57:14 +0200] "GET /.git/config HTTP/1.1" 404 4621 "-" "-"
show less
Brute-Force
๐ซ๐ท
masterguru
2026-08-17 18:54:19
(14 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 18:45:55
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 14:45:49.423081 2026] [security2:error] [pid 4254:tid 4254] [client 35.190.166.21:42476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marchmadness.projectthinkspot.com"] [uri "/.git/config"] [unique_id "aoNW3XXpzm4Ce14EWfb5WAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 18:24:29
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 14:24:24.206766 2026] [security2:error] [pid 9294:tid 9294] [client 35.190.166.21:52420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maps.marat.info"] [uri "/.git/config"] [unique_id "aoNR2BiA4hL9JatTD90MmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-17 18:23:51
(44 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-17 18:22:06
(46 minutes ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฟ
ddw
2026-08-17 18:09:18
(59 minutes ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 17:58:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 13:58:05.643375 2026] [security2:error] [pid 4600:tid 4600] [client 35.190.166.21:50506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manueltoren.com.dandemonium.net"] [uri "/.git/config"] [unique_id "aoNLrS4FRftTzOY0OSKqswAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
Olexiy Backend
2026-08-17 17:41:57
(1 hour ago)
35.190.166.21
...
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-08-17 17:40:56
(1 hour ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.190.166.21 - - [17/Aug/2026:20:40:55 +0300] "G ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: 35.190.166.21 - - [17/Aug/2026:20:40:55 +0300] "GET /.git/config HTTP/1.1" 404 808 "-" "-"
show less
Web App Attack
Anonymous
2026-08-17 17:38:26
(1 hour ago)
35.190.166.21 - - [18/Aug/2026:01:38:25 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "-"
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 17:38:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.166.21 (21.166.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 13:38:15.107660 2026] [security2:error] [pid 4700:tid 4700] [client 35.190.166.21:45590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manninglandservices.soviaenterprises.com"] [uri "/.git/config"] [unique_id "aoNHB3tXfg0JpU_B70TLcAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack