🇨🇭
leo1305
2026-09-03 08:11:17
(23 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
🇩🇪
dbmwebdesign
2026-09-03 08:05:06
(23 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇩🇪
Viveronese
2026-09-03 06:54:26
(1 day ago)
HTTP vulnerability scanning
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-03 04:56:26
(1 day ago)
[03/Sep/2026:07:56:26 +0300] -- 34.101.62.92 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[03/Sep/2026:07:56:26 +0300] -- 34.101.62.92 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 03:25:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 23:25:26.588185 2026] [security2:error] [pid 30540:tid 30540] [client 34.101.62.92:57062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "katzcreationz.celtickyss.com"] [uri "/src/.git/config"] [unique_id "apjopoQ5YLq_63Hl381OHwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 02:12:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
edena
2026-09-02 23:31:51
(1 day ago)
34.101.62.92 - - [03/Sep/2026:01:31:51 +0200] "GET /public/.git/config HTTP/1.1" 403 1842 "-" "crusa ...
show more
34.101.62.92 - - [03/Sep/2026:01:31:51 +0200] "GET /public/.git/config HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
34.101.62.92 - - [03/Sep/2026:01:31:51 +0200] "GET /api/.git/config HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
34.101.62.92 - - [03/Sep/2026:01:31:51 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 1842 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇫🇷
masterguru
2026-09-02 16:03:00
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇬🇧
consul.to
2026-09-02 14:30:46
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
vaia.cloud
2026-09-02 14:15:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:26:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:25:55.485684 2026] [security2:error] [pid 6080:tid 6080] [client 34.101.62.92:49082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahaciendaolivia.com"] [uri "/site/.git/config"] [unique_id "apgj41OMkUcWtwtMAEvqeQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
helios.live
2026-09-02 13:04:57
(1 day ago)
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92 ...
show more
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92, server: kocervpn.com, request: "GET /.git/config HTTP/1.1", host: "kocervpn.com"
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92, server: kocervpn.com, request: "GET /wordpress/.git/config HTTP/1.1", host: "kocervpn.com"
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92, server: kocervpn.com, request: "GET /var/www/.git/config HTTP/1.1", host: "kocervpn.com"
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92, server: kocervpn.com, request: "GET /api/.git/config HTTP/1.1", host: "kocervpn.com"
2026/09/02 13:04:57 [error] 3259141#3259141: *1949310 access forbidden by rule, client: 34.101.62.92, server: kocervpn.com, request: "GET /public/.git/config HTTP/1.1", host: "kocervpn.com"
...
show less
Web App Attack
Anonymous
2026-09-02 10:04:00
(1 day ago)
[elearning.zebs.ch] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/htdocs/.git/config | ...
show more
[elearning.zebs.ch] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/htdocs/.git/config | /html/.git/config | /api/.git/config
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 07:27:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.62.92 (92.62.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:26:57.529770 2026] [security2:error] [pid 2586:tid 2586] [client 34.101.62.92:41756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robk64.com"] [uri "/html/.git/config"] [unique_id "apfPwcD1TqdLeznPylaY0gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-02 06:13:59
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack