🇫🇷
masterguru
2026-08-29 09:16:34
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.14.127.221 (BE/Belgium/221.127.14. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.14.127.221 (BE/Belgium/221.127.14.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇸🇪
vaia.cloud
2026-08-29 09:05:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
gadix
2026-08-29 08:47:10
(1 day ago)
[29/Aug/2026:10:47:09.397678 +0200] apKcjY33e0z6OV7EZpweugAAAAg 34.14.127.221 46152 127.0.0.1 7081
[ ...
show more
[29/Aug/2026:10:47:09.397678 +0200] apKcjY33e0z6OV7EZpweugAAAAg 34.14.127.221 46152 127.0.0.1 7081
[29/Aug/2026:10:47:09.402362 +0200] apKcjfDbvZdy9hsx4BkwegAAAAQ 34.14.127.221 46154 127.0.0.1 7081
[29/Aug/2026:10:47:09.405912 +0200] apKcjffCbbMRpfMFvnu9vAAAAAY 34.14.127.221 46176 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:32:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:32:53.537126 2026] [security2:error] [pid 12891:tid 12891] [client 34.14.127.221:52354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ryanlowenstein.com"] [uri "/wordpress/.git/config"] [unique_id "apKZNQ9MQl5pWWqSVEDIfAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 06:40:01
(1 day ago)
suspicious request in access.log
Web App Attack
🇩🇪
stinpriza
2026-08-29 06:39:39
(1 day ago)
common Web Exploits being scanned
Web App Attack
🇷🇺
OK
2026-08-29 06:03:07
(1 day ago)
HTTP/HTTPS
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 03:28:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:28:03.836066 2026] [security2:error] [pid 1045:tid 1045] [client 34.14.127.221:36390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "36quant.com"] [uri "/src/.git/config"] [unique_id "apJRw8yZ05g0CHKWAyvjzAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 02:54:19
(1 day ago)
[osotir.org] httpd-config-scan: sites=www.new.logosparakliseos.gr; logs=/var/log/httpd/domains/logos ...
show more
[osotir.org] httpd-config-scan: sites=www.new.logosparakliseos.gr; logs=/var/log/httpd/domains/logosparakliseos.gr.new.log; samples=/api/.git/config | /wordpress/.git/config | /www/.git/config
show less
Hacking
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 01:53:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
BlueWire Hosting
2026-08-28 22:49:14
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:29:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.14.127.221 (221.127.14.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:29:44.247956 2026] [security2:error] [pid 19529:tid 19529] [client 34.14.127.221:41914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rgvatvrepair.com"] [uri "/.git/config"] [unique_id "apH9yFjwB0trqYP-RBeHIgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
DEV-DNS
2026-08-28 20:13:17
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇩🇪
Nightreaver
2026-08-28 19:05:07
(1 day ago)
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /backend/.git/config HTTP/1.1" 404 438 "-" "crus ...
show more
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /backend/.git/config HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /api/.git/config HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /www/.git/config HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /src/.git/config HTTP/1.1" 404 438 "-" "crusader-worker/1.0"
34.14.127.221 - - [28/Aug/2026:21:05:07 0200] "GET /site/.git/config HTTP/1.1" 404 438 "-" "crusader-worker/1.0"[...]
show less
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-28 14:01:32
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack