🇬🇧
openstrike.co.uk
2026-09-05 05:14:42
(20 hours ago)
12 attacks on VC URLs:
GET /html/.git/config HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-05 02:07:22
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:07:17.916926 2026] [security2:error] [pid 18837:tid 18837] [client 34.106.68.1:51932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.613.ninja"] [uri "/backend/.git/config"] [unique_id "apt5VaDsgyAXYSHI9UZezAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:00:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:00:23.997470 2026] [security2:error] [pid 6666:tid 6666] [client 34.106.68.1:53646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.spacebooger.com"] [uri "/api/.git/config"] [unique_id "aps_dwb9_DP_gMXxUQkyhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-04 21:50:15
(1 day ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:43:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:43:51.948411 2026] [security2:error] [pid 11247:tid 11247] [client 34.106.68.1:52314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cassandramari.com"] [uri "/backend/.git/config"] [unique_id "aps7l0JEuRJMVbTSxsWL7QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
TechnoSolutions CL
2026-09-04 20:59:16
(1 day ago)
34.106.68.1 - - [04/Sep/2026:20:59:15 +0000] "GET /app/.git/config HTTP/1.1" 444 0 "-" "crusader-wor ...
show more
34.106.68.1 - - [04/Sep/2026:20:59:15 +0000] "GET /app/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:20:59:15 +0000] "GET /api/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-04 20:54:04
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dock.budyn.wtf | URI: /.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 19:53:50
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 18:33:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:33:30.664881 2026] [security2:error] [pid 7375:tid 7375] [client 34.106.68.1:41246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3ddatacenters.com"] [uri "/html/.git/config"] [unique_id "apsO-sDGh9okF17TptRUcAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 17:57:17
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 16:29:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.68.1 (1.68.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:29:46.728524 2026] [security2:error] [pid 23622:tid 23635] [client 34.106.68.1:54954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danelandia.aafm.us"] [uri "/www/.git/config"] [unique_id "aprx-l-A3daoBIvuwmj1zQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 11:53:16
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
mnsf
2026-09-04 11:05:57
(1 day ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
Anonymous
2026-09-04 09:43:44
(1 day ago)
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crus ...
show more
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.106.68.1 - - [04/Sep/2026:11:43:44 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusa
...
show less
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 08:50:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack