π©πͺ
YF
2026-08-29 10:20:19
(1 day ago)
Git config exposure probe
Web App Attack
π¬π§
OptimusGO
2026-08-29 10:18:00
(1 day ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-29 11:18:00 UTC
Log evidence:
08/29/2026-11:17:59.932705 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.142.199.208:42932 -> 185.127.18.66:80
08/29/2026-11:17:59.938363 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.142.199.208:42936 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
Anonymous
2026-08-29 09:00:02
(2 days ago)
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusade ...
show more
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /app/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.142.199.208 - - [29/Aug/2026:11:00:01 +0200] "GET /site/.git/config HTTP/1.1" 403
...
show less
Bad Web Bot
Web App Attack
π©πͺ
Lino Project
2026-08-29 06:09:24
(2 days ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
πΊπΈ
TPI-Abuse
2026-08-29 04:29:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:29:22.045826 2026] [security2:error] [pid 21292:tid 21292] [client 34.142.199.208:58418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allotrope.com"] [uri "/wordpress/.git/config"] [unique_id "apJgIhbOUjRwW2AIp-wBMAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-29 02:22:45
(2 days ago)
Multiple WAF Violations
Web App Attack
π³π±
homeshowdomain.nl
2026-08-28 21:59:33
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
π³π±
WeCloudit-Anti-Abuse
2026-08-28 21:16:24
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 20:49:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:49:21.003783 2026] [security2:error] [pid 29804:tid 29812] [client 34.142.199.208:57122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.absurdotron.com"] [uri "/www/.git/config"] [unique_id "apH0UWUNw_Pa5vbYVDvbqgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
onlyops.app
2026-08-28 20:00:05
(2 days ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
π¨π¦
Anytech
2026-08-28 19:54:02
(2 days ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-28 17:49:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.199.208 (208.199.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:48:56.141652 2026] [security2:error] [pid 16743:tid 16743] [client 34.142.199.208:51038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ventilatori-industriali.mibfans.com"] [uri "/html/.git/config"] [unique_id "apHKCAAiUTnmef0yPIMkpQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 11:55:02
(2 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
kosada.com
2026-08-28 00:20:32
(3 days ago)
Web vulnerability probing: /backend/.git/config (bogus vhost/SNI)
Web App Attack
π―π΅
beon
2026-08-27 18:26:57
(3 days ago)
[DateTime=>2026-08-27T18:26:57Z (UTC)] , [HoneyPot_Hits=>24 times] , [HoneyPots=>/html/.git/config, ...
show more
[DateTime=>2026-08-27T18:26:57Z (UTC)] , [HoneyPot_Hits=>24 times] , [HoneyPots=>/html/.git/config, /api/.git/config, /site/.git/config, /htdocs/.git/config, /app/.git/config, /.git/config and others] , [total_Hits=>24 times] , [Keyword=>WordPress]
show less
Bad Web Bot
Web App Attack
Hacking