🇩🇪
patrisei
2026-08-29 05:13:11
(1 day ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
🇬🇧
consul.to
2026-08-29 00:38:17
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇮🇹
CoreTech srl
2026-08-29 00:18:56
(2 days ago)
cloudlinux2 fail2ban: 2026-08-29 02:15:46,734 fail2ban.filter [1478]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-29 02:15:46,734 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 130.49.79.60 - 2026-08-29 02:15:45cloudlinux2 fail2ban: 2026-08-29 02:16:26,529 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 65.108.72.254 - 2026-08-29 02:16:26cloudlinux2 fail2ban: 2026-08-29 02:16:47,197 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.106.170.246 - 2026-08-29 02:16:47cloudlinux2 fail2ban: 2026-08-29 02:16:47,174 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.106.170.246 - 2026-08-29 02:16:47cloudlinux2 fail2ban: 2026-08-29 02:16:47,183 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.106.170.246 - 2026-08-29 02:16:47cloudlinux2 fail2ban: 2026-08-29 02:16:47,239 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.106.170.246 - 2026-08-29 02:16:47cloudlinux2 fail2ban: 2026-08-29 02:16:47,230 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.106.170.246 - 2026-08-29 02:
show less
Web App Attack
🇺🇸
mnsf
2026-08-29 00:05:50
(2 days ago)
Too many Status 40X (12)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
WellSpring
2026-08-28 22:21:14
(2 days ago)
git exposure on 201.today/www/.git/config — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
🇨🇭
4server
2026-08-28 19:46:20
(2 days ago)
[FriAug2821:46:12.6104162026][security2:error][pid2773009:tid2773043][client34.106.170.246:0]ModSecu ...
show more
[FriAug2821:46:12.6104162026][security2:error][pid2773009:tid2773043][client34.106.170.246:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hosting-ticino-svizzera-com.ticino-hosting.ch\"][uri\"/var/www/.git/config\"][unique_id\"apHlhEXE5ILsRMOM4yWjWAAAAFI\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:41:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:41:44.510612 2026] [security2:error] [pid 24382:tid 24382] [client 34.106.170.246:51722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dry-rot.coretermite.com"] [uri "/backend/.git/config"] [unique_id "apHWaJGyVdv5Ah9PuUFNjAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:25:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:25:28.879894 2026] [security2:error] [pid 11178:tid 11270] [client 34.106.170.246:57056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.annastasiamason.com"] [uri "/backend/.git/config"] [unique_id "apHSmPS5qDu8MJf3feR2ngAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 17:49:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:49:29.455994 2026] [security2:error] [pid 12036:tid 12036] [client 34.106.170.246:33402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crossfiregold.com"] [uri "/wordpress/.git/config"] [unique_id "apHKKdGEgj1ZlH5bKU3hgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
OK
2026-08-28 17:17:05
(2 days ago)
HTTP/HTTPS
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-08-28 17:05:26
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 14:39:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:39:36.399378 2026] [security2:error] [pid 2754587:tid 2754642] [client 34.106.170.246:44180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saskiarose.m3sxa.com"] [uri "/wordpress/.git/config"] [unique_id "apGdqJVJy0gU-giJKURacQAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-08-28 12:14:43
(2 days ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
🇳🇴
jad-abuse
2026-08-28 11:27:39
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 36 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 10:36:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.170.246 (246.170.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:36:43.966077 2026] [security2:error] [pid 13592:tid 13592] [client 34.106.170.246:33960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.darkstarsystems.net"] [uri "/.git/config"] [unique_id "apFku_AIZUmpQRLzaVoPxQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack