๐ธ๐ช
vaia.cloud
2026-08-29 22:30:01
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-08-29 21:15:21
(2 days ago)
Bloqueado automaticamente por CrowdSec escenario crowdsecurity/http-sensitive-files
Brute-Force
๐ท๐ด
iulianh
2026-08-29 21:09:32
(2 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
Charlesiv
2026-08-29 20:02:50
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /site/.git/config
Timestamp: 2026-08-29T18:56:39Z
Ray ID: a32dc6e3ef2c3c0e
UA: crusader-worker/1.0
show less
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-08-29 18:58:47
(2 days ago)
Try to access /www/.git/config
Web App Attack
Anonymous
2026-08-29 15:21:00
(2 days ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐บ๐ธ
wteiken
2026-08-29 12:18:52
(2 days ago)
2026-08-29T08:18:49.097567-04:00 nostromo.teiken.net kernel: [122138.396403] syn_limit:IN=en-wan OUT ...
show more
2026-08-29T08:18:49.097567-04:00 nostromo.teiken.net kernel: [122138.396403] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.146.75.248 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=50914 DF PROTO=TCP SPT=45946 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-29T08:18:49.098076-04:00 nostromo.teiken.net kernel: [122138.396725] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.146.75.248 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=36392 DF PROTO=TCP SPT=45958 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-29T08:18:50.098992-04:00 nostromo.teiken.net kernel: [122139.397816] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.146.75.248 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=36393 DF PROTO=TCP SPT=45958 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-29T08:18:50.099371-04:00 nostromo.teiken.net kernel: [122139.398004] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:
...
show less
Port Scan
๐ฉ๐ช
LRob
2026-08-29 11:10:59
(2 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /var/www/.git/config (+11 more) | 2026-08-29 11:10 UTC
show less
Hacking
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-08-29 09:09:10
(2 days ago)
external host: 34.146.75.248 - - [29/Aug/2026:11:09:10 +0200] "GET /wordpress/.git/config HTTP/1.1" ...
show more
external host: 34.146.75.248 - - [29/Aug/2026:11:09:10 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 5744 "-" "crusader-worker/1.0" CF-Ray:- CF-IP:-
show less
Web App Attack
Anonymous
2026-08-28 23:33:23
(3 days ago)
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /public/.git/config HTTP/1.1" 403 12583 "-" "cru ...
show more
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /public/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /api/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /site/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /app/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /backend/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /html/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /www/.git/config HTTP/1.1" 403 12583 "-" "crusader-worker/1.0"
34.146.75.248 - - [29/Aug/2026:01:33:23 +0200] "GET /src/.git/config HTTP/1
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 17:27:37
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:13:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.146.75.248 (248.75.146.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.146.75.248 (248.75.146.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:13:13.969164 2026] [security2:error] [pid 741:tid 741] [client 34.146.75.248:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.distro.media"] [uri "/.git/config"] [unique_id "apGzmVPWc99MT0mvlNbeCwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 22:29:24
(4 days ago)
Web vulnerability probing: /html/.git/config (bogus vhost/SNI)
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 16:52:10
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-27 06:37:29
(5 days ago)
Web attack/malicious scanning detected
Web App Attack