🇺🇸
TPI-Abuse
2026-09-02 07:23:53
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:23:48.206892 2026] [security2:error] [pid 14118:tid 14118] [client 34.116.80.228:48246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robcruickshank.net"] [uri "/.git/config"] [unique_id "apfPBPI2ZHEPo8OE40MlTwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 06:12:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:12:01.124422 2026] [security2:error] [pid 14835:tid 14835] [client 34.116.80.228:52668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dragoldio.com"] [uri "/public/.git/config"] [unique_id "ape-MZMCpp5isEG9QQJxqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-02 04:03:45
(6 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-02 03:30:02
(6 days ago)
suspicious request in access.log
Web App Attack
🇩🇪
raph
2026-09-02 02:21:27
(6 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 01:07:28
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:07:21.502813 2026] [security2:error] [pid 19746:tid 19746] [client 34.116.80.228:51186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swwpccpa.com"] [uri "/html/.git/config"] [unique_id "apd2yeNTrGohi04uZh-_KwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
ciccio diddo
2026-09-02 00:44:02
(6 days ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 00:07:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:07:55.666549 2026] [security2:error] [pid 29502:tid 29502] [client 34.116.80.228:36778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.americanflagcards.com"] [uri "/www/.git/config"] [unique_id "apdo2zzUrkkyPUENdCDDVwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-01 18:27:41
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-01 18:25:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:25:29.129818 2026] [security2:error] [pid 24934:tid 24934] [client 34.116.80.228:42280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.aviil.net"] [uri "/htdocs/.git/config"] [unique_id "apcYmZJ-v1kMLW3w0SJkkAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-01 15:25:02
(1 week ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇧🇷
dominioz
2026-09-01 15:23:41
(1 week ago)
2026-09-01 15:23:20 GET /backend/.git/config - - 34.116.80.228 HTTP/1.1 crusader-worker/1.0 - 404 53 ...
show more
2026-09-01 15:23:20 GET /backend/.git/config - - 34.116.80.228 HTTP/1.1 crusader-worker/1.0 - 404 5366
2026-09-01 15:23:20 GET /site/.git/config - - 34.116.80.228 HTTP/1.1 crusader-worker/1.0 - 404 5360
2026-09-01 15:23:20 GET /.git/config - - 34.116.80.228 HTTP/1.1 crusader-worker/1.0 - 404 5350
2026-09-01 15:23:20 GET /htdocs/.git/config - - 34.116.80.228 HTTP/1.1 crusader-worker/1.0 - 404 5364
...
show less
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-01 10:05:42
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.116.80.228 (AU/Australia/228.80.116.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.116.80.228 (AU/Australia/228.80.116.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 09:19:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.116.80.228 (228.80.116.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:19:27.836088 2026] [security2:error] [pid 29738:tid 29876] [client 34.116.80.228:56292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "secretdecoded.com"] [uri "/www/.git/config"] [unique_id "apaYnwPlJnWS0sb9P1-eegAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 06:26:26
(1 week ago)
Web application attack detected.
Web App Attack