๐ธ๐ช
vaia.cloud
2026-09-01 18:15:01
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:05:43
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:05:36.587369 2026] [security2:error] [pid 5454:tid 5454] [client 34.148.91.218:43130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burke698.org"] [uri "/wordpress/.git/config"] [unique_id "apcT8ILF-ZyxIcK8hpyxcAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-01 15:19:11
(5 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 13:36:34
(6 hours ago)
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /.git/config HTTP/1.1" 403 4530 "-" "crusader-wo ...
show more
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /.git/config HTTP/1.1" 403 4530 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /src/.git/config HTTP/1.1" 404 4528 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /site/.git/config HTTP/1.1" 404 4529 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /app/.git/config HTTP/1.1" 404 4529 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /var/www/.git/config HTTP/1.1" 404 4528 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4529 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /www/.git/config HTTP/1.1" 404 4528 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /backend/.git/config HTTP/1.1" 404 4529 "-" "crusader-worker/1.0"
34.148.91.218 - - [01/Sep/2026:15:36:30 +0200] "GET /api/.git/config HTTP/1.1" 4
show less
Web App Attack
Hacking
๐ฉ๐ช
LRob
2026-09-01 08:41:09
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /wordpress/.git/config (+11 more) | 2026-09-01 08:41 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 06:05:12
(14 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:03:04
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:02:56.977352 2026] [security2:error] [pid 15336:tid 15336] [client 34.148.91.218:45004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calendarchristmascards.com"] [uri "/htdocs/.git/config"] [unique_id "apZOcCHfYxI2YA2wa7WGuQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:46:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:46:35.283344 2026] [security2:error] [pid 9701:tid 9785] [client 34.148.91.218:55834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "californiaplasticsurgeon.com.aafm.us"] [uri "/wordpress/.git/config"] [unique_id "apZKmzeTJ-AG_xCOHscI3wAAAgE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-30 00:05:31
(2 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:00:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.91.218 (218.91.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:00:09.397723 2026] [security2:error] [pid 31424:tid 31424] [client 34.148.91.218:49598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disenowebprofesional.com"] [uri "/api/.git/config"] [unique_id "apNWaTo-G5mVjdYG9e-1PwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-27 20:15:21
(5 days ago)
CMS/framework probe: 34.148.91.218 - - [27/Aug/2026:22:15:21 +0200] "GET /www/.git/config HTTP/1.1" ...
show more
CMS/framework probe: 34.148.91.218 - - [27/Aug/2026:22:15:21 +0200] "GET /www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 15:55:06
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 15:46:08
(5 days ago)
[27/Aug/2026:18:46:07 +0300] -- 34.148.91.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[27/Aug/2026:18:46:07 +0300] -- 34.148.91.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-27 13:00:42
(5 days ago)
Git config exposure probe
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 12:15:02
(5 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack