🇺🇸
TPI-Abuse
2026-08-29 09:52:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:51:53.626467 2026] [security2:error] [pid 23829:tid 23829] [client 34.123.42.205:39772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nsdorganogram.org"] [uri "/site/.git/config"] [unique_id "apKruXHrphXCQoF20ZbcJQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-08-29 09:45:05
(1 day ago)
34.123.42.205 - - [29/Aug/2026:11:45:04 +0200] "GET /.git/config HTTP/1.1" 302 403 "-" "crusader-wor ...
show more
34.123.42.205 - - [29/Aug/2026:11:45:04 +0200] "GET /.git/config HTTP/1.1" 302 403 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-08-29 07:33:43
(1 day ago)
Try to access /app/.git/config
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 07:33:23
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-29 07:00:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:00:25.867091 2026] [security2:error] [pid 13045:tid 13045] [client 34.123.42.205:40310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blisseventboutique.kawkacevents.com"] [uri "/html/.git/config"] [unique_id "apKDiTiH4m2VkB92saHhOwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-08-29 05:12:17
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-08-29 04:26:31
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.123.42.205 (US/United States/205 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.123.42.205 (US/United States/205.42.123.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
🇿🇦
conure.sh
2026-08-29 02:27:46
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:50:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:49:55.293615 2026] [security2:error] [pid 18173:tid 18173] [client 34.123.42.205:35460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oposicionesyconcursos.es.creartest.com"] [uri "/var/www/.git/config"] [unique_id "apI6wyvRFVJdit0rwujn6gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:17
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-08-28 16:47:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:47:52.675134 2026] [security2:error] [pid 21814:tid 21822] [client 34.123.42.205:47956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecraftsycat.theyogicat.com"] [uri "/html/.git/config"] [unique_id "apG7uCKc8ft05LGlSCefPgAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-08-28 16:26:53
(2 days ago)
common Web Exploits being scanned
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 16:06:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.123.42.205 (205.42.123.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:05:59.058338 2026] [security2:error] [pid 29145:tid 29145] [client 34.123.42.205:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ccamp.dev"] [uri "/.git/config"] [unique_id "apGx5_WrDCiXb74b8ZXFdwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-28 14:00:43
(2 days ago)
Multiple WAF Violations
Web App Attack
🇧🇪
sid3windr
2026-08-28 12:52:52
(2 days ago)
GET /.git/config (Tarpitted for 4m18s, wasted 15.23kB)
Web App Attack