🇺🇸
TPI-Abuse
2026-09-04 11:06:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:05:58.433679 2026] [security2:error] [pid 23736:tid 23736] [client 34.143.64.77:40302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.fairfieldfarms.net"] [uri "/wordpress/.git/config"] [unique_id "apqmFvAjJCv-s5Ged-13PQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:33:21
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:33:13.244476 2026] [security2:error] [pid 22991:tid 22991] [client 34.143.64.77:49976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oruguitas.org"] [uri "/.git/config"] [unique_id "appYGaK3hYLA1aQnzVG84gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 04:05:49
(10 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
Anonymous
2026-09-04 02:20:02
(12 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 22:15:42
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇬🇧
OptimusGO
2026-09-03 20:23:16
(18 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-03 21:23:16 UTC
Log evidence:
34.143.64.77 - - [03/Sep/2026:21:23:14 +0100] "GET /var/www/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.143.64.77 - - [03/Sep/2026:21:23:14 +0100] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.143.64.77 - - [03/Sep/2026:21:23:14 +0100] "GET /html/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
show less
Port Scan
Brute-Force
🇧🇪
cmbplf
2026-09-03 18:51:36
(19 hours ago)
389 requests with url.path */.git/config
Brute-Force
Bad Web Bot
🇫🇷
dynamix
2026-09-03 18:19:42
(20 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-03 15:08:03
(23 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 14:59:33
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:59:25.973879 2026] [security2:error] [pid 9242:tid 9242] [client 34.143.64.77:49690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrsreclamation.com"] [uri "/wordpress/.git/config"] [unique_id "apmLTQS1B36av2dWhP8SNwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 13:07:04
(1 day ago)
Automated web scanner. Requested suspicious paths: /src/.git/config | /backend/.git/config | /app/.g ...
show more
Automated web scanner. Requested suspicious paths: /src/.git/config | /backend/.git/config | /app/.git/config | /public/.git/config. UTC: 2026-09-03 13:06:34.
show less
Web App Attack
🇮🇹
VHosting
2026-09-03 09:55:08
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 08:59:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.64.77 (77.64.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:59:43.051158 2026] [security2:error] [pid 30757:tid 30757] [client 34.143.64.77:53392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hierrosbernal.ayudaclic.com"] [uri "/site/.git/config"] [unique_id "apk2_4Cctqc9jZ638vkyEwAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-09-03 08:17:11
(1 day ago)
CrowdSec at saturn Reports Abuse
Web App Attack
Anonymous
2026-09-03 06:31:32
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking