🇺🇸
TPI-Abuse
2026-09-09 15:07:40
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:07:33.609014 2026] [security2:error] [pid 25409:tid 25409] [client 35.233.178.9:53250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cursoastrologia.verdadesreales.com"] [uri "/.git/config"] [unique_id "aqF2NZHiFLpJPyYr0pjDcAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 15:05:30
(13 minutes ago)
35.233.178.9 - - [09/Sep/2026:15:05:29 +0000] "GET /.git/config HTTP/1.1" 404 7866 "-" "-"
...
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:49:42
(29 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:49:37.602906 2026] [security2:error] [pid 22321:tid 22321] [client 35.233.178.9:60048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cthog.z-mgmt.com"] [uri "/.git/config"] [unique_id "aqFyAf6yVykZ-g5nacCEVAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 14:48:16
(30 minutes ago)
apache vulnerability scan
Web App Attack
🇭🇺
bcsaba
2026-09-09 14:38:56
(40 minutes ago)
Probing for .git:
35.233.178.9 - - [09/Sep/2026:16:38:54 +0200] "GET /.git/config HTTP/1.1" 403 146 ...
show more
Probing for .git:
35.233.178.9 - - [09/Sep/2026:16:38:54 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "-"
show less
Web App Attack
🇵🇾
armandosaucedo.me
2026-09-09 14:33:13
(45 minutes ago)
Threat Intelligence via ARMTI, Web Attack: GET /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:30:35
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:30:28.559123 2026] [security2:error] [pid 32118:tid 32118] [client 35.233.178.9:48574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.crushmycrave.ficklepassionproductions.com"] [uri "/.git/config"] [unique_id "aqFthOLtmRGpVn7J6m0bvAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
IVski.com
2026-09-09 14:15:37
(1 hour ago)
IVski WAF | Sensitive file probe - looking for exposed .git/config
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:09:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.178.9 (9.178.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:09:34.270806 2026] [security2:error] [pid 7351:tid 7351] [client 35.233.178.9:55632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cristalsupermercado.gp.com.grupoporvenir.com"] [uri "/.git/config"] [unique_id "aqFonsEfmsF7xMO3RxGD6AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 14:06:44
(1 hour ago)
Trying to access config files
Web App Attack
🇺🇸
mnsf
2026-09-09 14:05:38
(1 hour ago)
Abuse Detected (25)
Brute-Force
Web App Attack
Anonymous
2026-09-09 14:05:24
(1 hour ago)
Scan for .git Files at 2026-09-09T14:05:24+00:00
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-09 13:57:02
(1 hour ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa02]
Hacking
SQL Injection
Web App Attack
🇳🇱
mieg
2026-09-09 13:55:47
(1 hour ago)
Web vulnerability probing
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-09 13:53:15
(1 hour ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-09 13:53 UTC
show less
Hacking
Web App Attack