๐บ๐ธ
mnsf
2026-09-02 09:05:19
(5 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:20:08
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:20:04.913080 2026] [security2:error] [pid 4592:tid 4592] [client 34.106.202.165:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.earscript.net"] [uri "/backend/.git/config"] [unique_id "apfcNF6KvLjo8L2_Qe_sLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 07:50:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:50:30.579739 2026] [security2:error] [pid 29102:tid 29108] [client 34.106.202.165:40004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalfellows.com.aafm.us"] [uri "/backend/.git/config"] [unique_id "apfVRogZ-jMajD4D6QjVpAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 05:37:36
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 05:32:34
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:32:27.267499 2026] [security2:error] [pid 21037:tid 21037] [client 34.106.202.165:45400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.tripptavern.com"] [uri "/backend/.git/config"] [unique_id "ape064-b2BVLdEl49InvcAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 05:16:11
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 05:12:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:12:03.073372 2026] [security2:error] [pid 3576:tid 3576] [client 34.106.202.165:52038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.newcastle91.org"] [uri "/backend/.git/config"] [unique_id "apewI2dR9RXZfxNbQUbPnQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-02 02:38:59
(11 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-02 02:12:13
(11 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /src/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-02 00:45:02
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:11:22
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:11:17.416737 2026] [security2:error] [pid 31704:tid 31704] [client 34.106.202.165:47134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gmes.biz"] [uri "/.git/config"] [unique_id "apdppdcq6AXHVayORzq2tQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:40:09
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.202.165 (165.202.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:40:03.046798 2026] [security2:error] [pid 27539:tid 27539] [client 34.106.202.165:34310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomorrowsdust.net.greighhouse.com"] [uri "/www/.git/config"] [unique_id "apdUQ4vrdtNy-fKV4McAawAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-01 21:25:10
(16 hours ago)
Web App Attack
๐ฉ๐ช
on-com
2026-09-01 21:17:35
(16 hours ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
Gabriel Camargo
2026-09-01 18:01:59
(20 hours ago)
34.106.202.165 - - [01/Sep/2026:13:01:59 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-wo ...
show more
34.106.202.165 - - [01/Sep/2026:13:01:59 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.106.202.165 - - [01/Sep/2026:13:01:59 -0500] "GET /app/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.106.202.165 - - [01/Sep/2026:13:01:59 -0500] "GET /backend/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH