๐ฉ๐ช
robotstxt
2026-09-24 09:00:28
(17 hours ago)
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /app/.git/config HTTP/1.1" 403 189 "-" "crusade ...
show more
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /app/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.118.175.106"
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /api/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.118.175.106"
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /src/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.118.175.106"
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /htdocs/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.118.175.106"
34.118.175.106 - - [24/Sep/2026:08:59:25 +0000] "GET /html/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="34.118.175.106"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:45:39
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:45:33.847000 2026] [security2:error] [pid 4845:tid 4845] [client 34.118.175.106:32774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "delomel.net"] [uri "/backend/.git/config"] [unique_id "arTjLSIdnsJawJjnCboZxgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 07:51:01
(18 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /var/www/.git/config (+11 more) | 2026-09-24 07:51 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 07:06:04
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:30:40
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:30:32.896728 2026] [security2:error] [pid 2719:tid 2719] [client 34.118.175.106:35838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creativemediacommunications.cmcnow.net"] [uri "/.git/config"] [unique_id "arSnaERnhodWGG8RptF9xgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-24 03:45:17
(22 hours ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:42:07
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:42:01.637053 2026] [security2:error] [pid 27726:tid 27726] [client 34.118.175.106:59678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sympalais.com"] [uri "/.git/config"] [unique_id "arSN-QLeII0g2IjJxBxk8gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:15:00
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:14:56.666153 2026] [security2:error] [pid 4153:tid 4153] [client 34.118.175.106:37388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.lavozdominicana.com"] [uri "/backend/.git/config"] [unique_id "arSHoBseK8JkdRKojsPmNQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:29:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:29:03.583761 2026] [security2:error] [pid 5765:tid 5765] [client 34.118.175.106:39586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wa211.org"] [uri "/src/.git/config"] [unique_id "arR833tjMU3rGplm7o8RGQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 00:25:06
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:17:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:17:36.625937 2026] [security2:error] [pid 17008:tid 17008] [client 34.118.175.106:42274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.davidsonmanagement.net"] [uri "/api/.git/config"] [unique_id "arRsIA39EV-oi-43NXxm0gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 23:26:32
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-23 23:05:28
(1 day ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:41:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:41:54.735999 2026] [security2:error] [pid 22092:tid 22092] [client 34.118.175.106:34984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cleanbuildingservices.com"] [uri "/html/.git/config"] [unique_id "arQ5kjsG3WTDqb8EBWTxbwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:52:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.175.106 (106.175.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:52:49.770175 2026] [security2:error] [pid 19308:tid 19308] [client 34.118.175.106:59650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caminorfoundation.org"] [uri "/www/.git/config"] [unique_id "arQD4bDmF8Ci6Km5SZEG9AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack