๐บ๐ธ
TPI-Abuse
2026-06-15 09:27:29
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:27:23.533461 2026] [security2:error] [pid 27020:tid 27020] [client 35.244.118.34:33886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geriart.net"] [uri "/api/.git/config"] [unique_id "ai_Fe1pt4JR5fx5c-yUIaAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
elcruzado.es
2026-06-15 08:41:39
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.244.118.34 (AU/Australia/34.118.244. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.244.118.34 (AU/Australia/34.118.244.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-06-15 08:03:40
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 08:02:49
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:02:40.542255 2026] [security2:error] [pid 3891:tid 3908] [client 35.244.118.34:42150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/app/.git/config"] [unique_id "ai-xoMX-eEm1Gzy1DSF25wAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 07:38:33
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-06-15 07:38:06
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /public/.git/config HTTP/1.1, GET /web/.git/config HTTP/ ...
show more
Bot / scanning and/or hacking attempts: GET /public/.git/config HTTP/1.1, GET /web/.git/config HTTP/1.1, GET /htdocs/.git/config HTTP/1.1, GET /build/.git/config HTTP/1.1, GET /api/.git/config HTTP/1.1, GET /symfony/.git/config HTTP/1.1, GET /code/.git/config HTTP/1.1, GET /v2/.git/config HTTP/1.1, GET /laravel/.git/config HTTP/1.1, GET /v3/.git/config HTTP/1.1, GET /html/.git/config HTTP/1.1, GET /portal/.git/config HTTP/1.1, GET /dashboard/.git/config HTTP/1.1, GET /src/.git/config HTTP/1.1, GET /wp-content/.git/config HTTP/1.1, GET /backend/.git/config HTTP/1.1, GET /shop/.git/config HTTP/1.1, GET /www/.git/config HTTP/1.1, GET /site/.git/config HTTP/1.1, GET /assets/.git/config HTTP/1.1, GET /admin/.git/config HTTP/1.1, GET /.git/config HTTP/1.1, GET /static/.git/config HTTP/1.1
show less
Hacking
Web App Attack
๐จ๐ฆ
electronico
2026-06-15 07:08:35
(5 hours ago)
35.244.118.34 - - [15/Jun/2026:18:08:34 +1100] "GET /src/.git/config HTTP/1.1" 404 4309 "-" "Mozilla ...
show more
35.244.118.34 - - [15/Jun/2026:18:08:34 +1100] "GET /src/.git/config HTTP/1.1" 404 4309 "-" "Mozilla/5.0 (iPad; CPU OS 13_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) GSA/79.0.259819395 Mobile/17A5556d Safari/604.1"
35.244.118.34 - - [15/Jun/2026:18:08:34 +1100] "GET /admin/.git/config HTTP/1.1" 404 4309 "-" "Screaming Frog SEO Spider/8.1"
35.244.118.34 - - [15/Jun/2026:18:08:34 +1100] "GET /shop/.git/config HTTP/1.1" 404 4309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_0) AppleWebKit/536.3 (KHTML, like Gecko) Chrome/19.0.1063.0 Safari/536.3"
35.244.118.34 - - [15/Jun/2026:18:08:35 +1100] "GET /v1/.git/config HTTP/1.1" 404 4309 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36"
35.244.118.34 - - [15/Jun/2026:18:08:35 +1100] "GET /static/.git/config HTTP/1.1" 404 4309 "-" "Mozilla/5.0 (Linux; Android 8.1.0; Moto G (5S) Plus) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 Mobile Sa
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-06-15 06:00:23
(6 hours ago)
common Web Exploits being scanned
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 03:24:38
(8 hours ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:22:50
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.118.34 (34.118.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:22:43.344124 2026] [security2:error] [pid 16590:tid 16590] [client 35.244.118.34:47372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brychta.net"] [uri "/htdocs/.git/config"] [unique_id "ai9wAwHpD8tbiiBzxLJ_xgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 02:26:45
(9 hours ago)
20 attempts against mh-misbehave-ban on hostbilldev
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dominioz
2026-06-15 01:42:17
(10 hours ago)
2026-06-15 01:42:12 GET /public/.git/config - - 35.244.118.34 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_6 ...
show more
2026-06-15 01:42:12 GET /public/.git/config - - 35.244.118.34 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Ubuntu+Chromium/65.0.3325.181+Chrome/65.0.3325.181+Safari/537.36 - 301 541
2026-06-15 01:42:12 GET /v1/.git/config - - 35.244.118.34 HTTP/1.1 Mozilla/5.0+(Windows+NT+6.1;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/73.0.3683.86+Safari/537.36 - 301 533
2026-06-15 01:42:12 GET /html/.git/config - - 35.244.118.34 HTTP/1.1 Mozilla/5.0+(Linux;+Android+8.0.0;+moto+e5+plus+Build/OPPS27.91-122-3)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/66.0.3359.126+Mobile+Safari/537.36 - 301 537
2026-06-15 01:42:12 GET /dashboard/.git/config - - 35.244.118.34 HTTP/1.1 Mozilla/5.0+(SymbianOS/9.1;+U;+de)+AppleWebKit/413+(KHTML,+like+Gecko)+Safari/413 - 301 547
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 01:34:49
(10 hours ago)
30 attempts against mh_ha-misbehave-ban on taro
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-15 01:26:25
(10 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
1gz
2026-06-15 01:20:48
(10 hours ago)
Triggered Cloudflare WAF (bic) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint ...
show more
Triggered Cloudflare WAF (bic) from AU.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /dist/.git/config
UA: Mozilla/5.0 (X11; U; Linux i686; pl-PL; rv:1.9.0.2) Gecko/20121223 Ubuntu/9.25 (jaunty) Firefox/3.8
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot