🇺🇸
wbsouza
2026-09-05 03:29:20
(21 hours ago)
CrowdSec: crowdsecurity/http-sensitive-files — automated firewall drops on self-hosted IDS sensor
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 02:34:05
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-05 01:41:24
(23 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-05 01:38:11
(23 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:47
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
Anonymous
2026-09-04 21:57:11
(1 day ago)
2026/09/04 21:57:09 [error] 3174957#3174957: *187329 [client 207.175.131.200] ModSecurity: Access de ...
show more
2026/09/04 21:57:09 [error] 3174957#3174957: *187329 [client 207.175.131.200] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "mail.royalealmond.com"] [uri "/.git/config"] [unique_id "178855902913.428152"] [ref ""], client: 207.175.131.200, server: srv.ingeltechgh.com, request: "GET /.git/config HTTP/1.1", host: "mail.royalealmond.com"
2026/09/04 21:57:09 [error] 3174956#3174956: *187328 [client 207.175.131.200] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5'
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 21:43:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:43:08.088146 2026] [security2:error] [pid 6142:tid 6142] [client 207.175.131.200:41206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.patriot-storage.com"] [uri "/app/.git/config"] [unique_id "aps7bI8QgjBY8BJw8KiViwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-04 21:21:06
(1 day ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
🇩🇪
4server
2026-09-04 18:13:54
(1 day ago)
[FriSep0420:13:51.9468372026][security2:error][pid494819:tid494911][client207.175.131.200:0]ModSecur ...
show more
[FriSep0420:13:51.9468372026][security2:error][pid494819:tid494911][client207.175.131.200:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"traslochiamo.ch\"][uri\"/html/.git/config\"][unique_id\"apsKX8O5wyFiJeTRKjIqoQAAAQM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:51:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:51:02.007938 2026] [security2:error] [pid 12376:tid 12376] [client 207.175.131.200:58228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dartylife.com"] [uri "/site/.git/config"] [unique_id "apr29qQdhVVv943-k2U4qwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:50:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:50:25.599597 2026] [security2:error] [pid 31502:tid 31502] [client 207.175.131.200:51334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.buggyshop.org"] [uri "/src/.git/config"] [unique_id "aprowecXu8rwOtLosfNVQAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:43:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:43:13.228336 2026] [security2:error] [pid 3195503:tid 3195622] [client 207.175.131.200:40192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emehache.com"] [uri "/html/.git/config"] [unique_id "aprZAUj7yHX7KVVl_0g_iQAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:54:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:54:19.934202 2026] [security2:error] [pid 25087:tid 25087] [client 207.175.131.200:49794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.volollc.com"] [uri "/app/.git/config"] [unique_id "apqxa7e2CUizunlbtDtoDAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:24:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.131.200 (200.131.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:24:40.415489 2026] [security2:error] [pid 25895:tid 25895] [client 207.175.131.200:40030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rallentarecg.com"] [uri "/var/www/.git/config"] [unique_id "appyOIDPulwnWdjejQ5HZQAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-09-04 05:40:55
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 207.175.131.200 (BE/Belgium/200.131 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 207.175.131.200 (BE/Belgium/200.131.175.207.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack