🇬🇧
consul.to
2026-09-05 23:42:28
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:09:19
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:09:16.467669 2026] [security2:error] [pid 7390:tid 7390] [client 34.104.141.26:50788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rkevinschneider.com"] [uri "/wordpress/.git/config"] [unique_id "apyE_HDO56eO62rAPvwA0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 13:52:56
(13 hours ago)
Sep 5 15:52:54 mail2 Nextcloud[131555]: {"reqId":"apwetusPQIUnCkfDb0XnYwAAAdE","level":1,"time":"20 ...
show more
Sep 5 15:52:54 mail2 Nextcloud[131555]: {"reqId":"apwetusPQIUnCkfDb0XnYwAAAdE","level":1,"time":"2026-09-05T13:52:54+00:00","remoteAddr":"34.104.141.26","user":"--","app":"core","method":"GET","url":"/htdocs/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.104.141.26\" tried to access using \"mail2.akcurate.de\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 15:52:54 mail2 Nextcloud[118565]: {"reqId":"apwetinwjflWVpOEbUr05wAAAZg","level":1,"time":"2026-09-05T13:52:54+00:00","remoteAddr":"34.104.141.26","user":"--","app":"core","method":"GET","url":"/api/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.104.141.26\" tried to access using \"mail2.akcurate.de\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.9.2","data":{"app":"core"}}
Sep 5 15:52:54 mail2 Nextcloud[126720]: {"reqId":"apwetidMOxd68GB5_T3AuAAAAU4","level":1,"time":"2026-09-05T13:52:54+00:00","remoteAddr":"34
...
show less
Brute-Force
Web App Attack
🇺🇸
Carltonfsck
2026-09-05 10:50:28
(16 hours ago)
34.104.141.26 - - [05/Sep/2026:10:50:28 +0000] "GET / HTTP/1.0" 400 402
34.104.141.26 - - [05/Sep/20 ...
show more
34.104.141.26 - - [05/Sep/2026:10:50:28 +0000] "GET / HTTP/1.0" 400 402
34.104.141.26 - - [05/Sep/2026:10:50:28 +0000] "GET / HTTP/1.0" 400 402
34.104.141.26 - - [05/Sep/2026:10:50:28 +0000] "GET / HTTP/1.0" 400 402
...
show less
Hacking
Brute-Force
🇳🇱
javierin
2026-09-05 01:35:16
(1 day ago)
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /site/.git/config HT ...
show more
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /site/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /src/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /backend/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /public/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /var/www/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /api/.git/config HTTP/1.1" 404 19565 "-" "crusader-worker/1.0"
34.104.141.26 - xn--nombres-de-nio-2nb.es - - [05/Sep/2026:01:35:15 +0000] "GET /.git/config HTTP/1.1" 404 19565 "-" "crusader-wor
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:02:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:02:32.040105 2026] [security2:error] [pid 19750:tid 19750] [client 34.104.141.26:54398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.grandpont-house.org"] [uri "/wordpress/.git/config"] [unique_id "apsx6Ha5VwEHhdUhMqGMUwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 19:22:27
(1 day ago)
Multiple WAF Violations
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 19:00:53
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
kosada.com
2026-09-04 17:44:03
(1 day ago)
Repeated exploit attempts, for example: /src/.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:46:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:46:16.663523 2026] [security2:error] [pid 21360:tid 21360] [client 34.104.141.26:59954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.entetanimiento.com"] [uri "/www/.git/config"] [unique_id "aprnyMmUpqSPHMc0cVRy0gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:55:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:55:52.159682 2026] [security2:error] [pid 3195503:tid 3195601] [client 34.104.141.26:58146] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emehache.net"] [uri "/.git/config"] [unique_id "aprb-Ej7yHX7KVVl_0hFcwAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 14:03:34
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-04 12:05:09
(1 day ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:52:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:52:32.517857 2026] [security2:error] [pid 18984:tid 18984] [client 34.104.141.26:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.mail-pmg.com"] [uri "/html/.git/config"] [unique_id "apqxABMxkjEmm41dHdbxMAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:11:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.141.26 (26.141.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:11:50.854673 2026] [security2:error] [pid 29907:tid 29907] [client 34.104.141.26:53710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "areafinancieratf.com"] [uri "/api/.git/config"] [unique_id "apqZZqTDTLh_5Qw6OEUE7gAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack