Anonymous
2026-08-28 15:35:49
(1 day ago)
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 12583 "-" "cru ...
show more
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /site/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /var/www/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /src/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /www/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /backend/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /app/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.128.92.220 - - [28/Aug/2026:17:35:48 +0200] "GET /html/.git/config HT
...
show less
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-28 12:46:52
(1 day ago)
[FriAug2814:46:45.9830812026][security2:error][pid2652959:tid2653125][client34.128.92.220:0]ModSecur ...
show more
[FriAug2814:46:45.9830812026][security2:error][pid2652959:tid2653125][client34.128.92.220:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.archi-box.ch\"][uri\"/html/.git/config\"][unique_id\"apGDNT75hyEpeE0QtkCTKAAAAEg\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 11:47:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:47:48.268520 2026] [security2:error] [pid 31910:tid 31910] [client 34.128.92.220:46568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lifeinsmoke.yeejia.net"] [uri "/src/.git/config"] [unique_id "apF1ZPV_UQ-pYBSx_vrklAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-08-28 11:33:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-28 13:29:00,364 fail2ban.actions [1478]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 13:29:00,364 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 34.125.254.12cloudlinux2 fail2ban: 2026-08-28 13:28:59,662 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 157.22.46.92 - 2026-08-28 13:28:59cloudlinux2 fail2ban: 2026-08-28 13:29:06,382 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 8.234.164.204cloudlinux2 fail2ban: 2026-08-28 13:30:10,525 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 216.73.160.60 - 2026-08-28 13:30:09cloudlinux2 fail2ban: 2026-08-28 13:30:36,304 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 84.115.239.31 - 2026-08-28 13:30:36cloudlinux2 fail2ban: 2026-08-28 13:30:53,971 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.128.92.220 - 2026-08-28 13:30:53cloudlinux2 fail2ban: 2026-08-28 13:30:53,954 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.128.92.220 - 2026-08-28 13:30:53cloudlinux2 fail2ban: 2026-08-28 13:30:53,97
show less
Web App Attack
🇬🇧
consul.to
2026-08-28 10:52:15
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
kosada.com
2026-08-27 23:13:09
(2 days ago)
Web vulnerability probing: /api/.git/config
Web App Attack
🇦🇺
2000cn.com.au
2026-08-27 22:50:10
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
ipoac.nl
2026-08-27 21:41:14
(2 days ago)
ipoac.nl:443 34.128.92.220 - - [27/Aug/2026:23:41:13 +0200] 203.26.133.254 "GET /public/.git/config ...
show more
ipoac.nl:443 34.128.92.220 - - [27/Aug/2026:23:41:13 +0200] 203.26.133.254 "GET /public/.git/config HTTP/1.1" 404 6373 "-" "crusader-worker/1.0"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-27 19:01:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:00:52.877524 2026] [security2:error] [pid 23669:tid 23669] [client 34.128.92.220:40864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.williammaderas.com"] [uri "/src/.git/config"] [unique_id "apCJZIaiuIOFrjeZUfViRQAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:25:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:25:33.416879 2026] [security2:error] [pid 32031:tid 32031] [client 34.128.92.220:49986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wiltoncheese.com.modeltdr.com"] [uri "/.git/config"] [unique_id "apBzDXG_CX0eZOkYJK6k_QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-08-27 14:17:01
(2 days ago)
A.i.D.A.N.N ML: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 13:12:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:12:00.995090 2026] [security2:error] [pid 20250:tid 20250] [client 34.128.92.220:45788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.phuketyachtrentals.com"] [uri "/htdocs/.git/config"] [unique_id "apA3oLwqcOyzRkZpSp0xYAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
itsolon
2026-08-27 10:38:41
(2 days ago)
[27/Aug/2026:12:38:41 +0200] 178782712117.394090 34.128.92.220 60270 217.154.7.177 443
[27/Aug/2026: ...
show more
[27/Aug/2026:12:38:41 +0200] 178782712117.394090 34.128.92.220 60270 217.154.7.177 443
[27/Aug/2026:12:38:41 +0200] 178782712181.848820 34.128.92.220 60254 217.154.7.177 443
[27/Aug/2026:12:38:41 +0200] 178782712163.878333 34.128.92.220 60316 217.154.7.177 443
[27/Aug/2026:12:38:41 +0200] 178782712199.979885 34.128.92.220 60276 217.154.7.177 443
[27/Aug/2026:12:38:41 +0200] 178782712140.097909 34.128.92.220 60330 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 08:39:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.92.220 (220.92.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:39:33.823345 2026] [security2:error] [pid 2225196:tid 2225227] [client 34.128.92.220:54764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.the-aquifer.com.giere.us"] [uri "/backend/.git/config"] [unique_id "ao_3xRThUDYzoODW_71_UAAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
febrian.de
2026-08-27 08:36:21
(2 days ago)
Excessive HTTP(S) probing or bad web bot detected by Fail2Ban
Bad Web Bot
Web App Attack