๐บ๐ธ
TPI-Abuse
2026-06-14 05:25:49
(41 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:25:41.537942 2026] [security2:error] [pid 6698:tid 6698] [client 34.131.100.141:36288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caminorfoundation.org"] [uri "/v3/.git/config"] [unique_id "ai47Va9y6dSMOnNEj0JkDgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-06-14 04:44:00
(1 hour ago)
http-sensitive-files - IP: 34.131.100.141 - time="2026-06-14T06:43:59+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 34.131.100.141 - time="2026-06-14T06:43:59+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.131.100.141 (IN/396982) : 4h ban on Ip 34.131.100.141" module=db
show less
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-14 04:04:11
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 03:30:04
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 23:29:58.496442 2026] [security2:error] [pid 20329:tid 20329] [client 34.131.100.141:38008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "reporting.thereddoorlounge.com"] [uri "/public/.git/config"] [unique_id "ai4gNtYDIjPiR-nQYXc6tgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-14 03:12:20
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /v1/.git/config | Evidence: www.zaviturviajes.com ...
show more
Web scanning / probing for vulnerable paths | URL: /v1/.git/config | Evidence: www.zaviturviajes.com 34.131.100.141 - - [14/Jun/2026:05:12:02 +0200] \"GET /v1/.git/config HTTP/1.1\" 404 4005 \"-\" \"Mozilla/5.0 (Linux; Android 8.1.0; Redmi Y2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36\" GEOIP_COUNTRY_CODE=IN | ASN: GOOGLE-CLOUD-PLATFORM | Country: IN
show less
Port Scan
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-14 02:52:21
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-14 02:49:04
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 02:43:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.100.141 (141.100.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:43:36.488499 2026] [security2:error] [pid 20216:tid 20225] [client 34.131.100.141:37058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agqo.org"] [uri "/backend/.git/config"] [unique_id "ai4VWHFYHTlLDE1PmXEyEwAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 02:05:44
(4 hours ago)
Too many Status 40X (13)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-06-14 01:50:03
(4 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
Ano_Nym
2026-06-13 21:45:02
(8 hours ago)
CrowdSec IDS alert on VPS 85.215.198.123 (DE). Scenario: crowdsecurity/http-sensitive-files
Web App Attack