🇩🇪
dbmwebdesign
2026-08-28 16:50:03
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇧🇪
sid3windr
2026-08-28 15:30:30
(2 days ago)
GET /.git/config (Tarpitted for 2m8s, wasted 7.62kB)
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 13:35:04
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
XICTRON
2026-08-28 13:10:07
(2 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
mnsf
2026-08-28 12:05:36
(2 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 11:46:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:46:31.779385 2026] [security2:error] [pid 22603:tid 22603] [client 34.139.211.0:57462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fingershrine.com"] [uri "/var/www/.git/config"] [unique_id "apF1F4yBPw3P3ZdbeOsc9AAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-08-27 23:32:17
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-27 22:01:14
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-27 18:05:02
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 17:58:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:57:58.554781 2026] [security2:error] [pid 14924:tid 14924] [client 34.139.211.0:56002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thestardance.stardancertantra.com"] [uri "/html/.git/config"] [unique_id "apB6pnncyjidhkft1lHczAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 16:41:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:40:58.833308 2026] [security2:error] [pid 13922:tid 13922] [client 34.139.211.0:60852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/site/.git/config"] [unique_id "apBomleQfZzts3HcxGGUKgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-08-27 13:06:33
(3 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇸🇪
nekopavel
2026-08-27 12:56:44
(3 days ago)
34.139.211.0 - - [27/Aug/2026:14:56:42 +0200]"GET /site/.git/config HTTP/1.1" 404 1456"-" de3.dorito ...
show more
34.139.211.0 - - [27/Aug/2026:14:56:42 +0200]"GET /site/.git/config HTTP/1.1" 404 1456"-" de3.dorito.pavel.gg "crusader-worker/1.0""0.000" "-""North Charleston" "US"
34.139.211.0 - - [27/Aug/2026:14:56:42 +0200]"GET /www/.git/config HTTP/1.1" 404 1456"-" de3.dorito.pavel.gg "crusader-worker/1.0""0.000" "-""North Charleston" "US"
34.139.211.0 - - [27/Aug/2026:14:56:42 +0200]"GET /public/.git/config HTTP/1.1" 404 1456"-" de3.dorito.pavel.gg "crusader-worker/1.0""0.000" "-""North Charleston" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-27 08:27:56
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 07:02:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.211.0 (0.211.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:02:00.611565 2026] [security2:error] [pid 14748:tid 14748] [client 34.139.211.0:56484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.agingworkforcenews.com"] [uri "/site/.git/config"] [unique_id "ao_g6L1K7Vi6_bkR7j6dYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack