๐ฉ๐ช
FeG Deutschland
2026-08-29 01:14:16
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 00:19:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:19:24.818940 2026] [security2:error] [pid 8251:tid 8251] [client 34.152.11.89:51468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jdubindustries.com"] [uri "/var/www/.git/config"] [unique_id "apIljHrrM_fWIGIKSu7LPAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:09
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-08-28 16:21:51
(4 days ago)
Scan for .git Files at 2026-08-28T16:21:51+00:00
Web App Attack
๐ง๐ช
Ivo Vynckier
2026-08-28 15:20:00
(4 days ago)
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 157 "-" "cru ...
show more
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /backend/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /public/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /var/www/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:15:12:02 +0200] "GET /html/.git/config HTTP/1.1" 403 157 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ซ๐ฎ
as211431.net
2026-08-28 13:36:15
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /www/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 11:55:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:55:42.450142 2026] [security2:error] [pid 26211:tid 26211] [client 34.152.11.89:46940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.agingworkforcenews.com"] [uri "/app/.git/config"] [unique_id "apF3PsZUzFHF2gALxzqJHgAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 02:05:09
(4 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:44:18
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:44:14.493635 2026] [security2:error] [pid 19537:tid 19537] [client 34.152.11.89:44628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/app/.git/config"] [unique_id "apDLzuhygVwab_JwdnDywQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 18:40:03
(5 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-27 15:50:15
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-27 15:38:17
(5 days ago)
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /.git/config HTTP/1.1" 403 4438 "-" "crusader-wor ...
show more
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /.git/config HTTP/1.1" 403 4438 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /htdocs/.git/config HTTP/1.1" 301 4753 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /app/.git/config HTTP/1.1" 301 4749 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /.git/config HTTP/1.1" 301 543 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /wordpress/.git/config HTTP/1.1" 301 4754 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /html/.git/config HTTP/1.1" 301 4749 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /src/.git/config HTTP/1.1" 301 4750 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /var/www/.git/config HTTP/1.1" 301 4752 "-" "crusader-worker/1.0"
34.152.11.89 - - [27/Aug/2026:17:38:12 +0200] "GET /api/.git/config HTTP/1.1" 301 4749 "-"
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 13:19:33
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:19:27.324569 2026] [security2:error] [pid 30820:tid 30820] [client 34.152.11.89:41984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitelabelcasinoportal.net"] [uri "/app/.git/config"] [unique_id "apA5X_AidXX9faBnNAncpAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-08-27 12:31:29
(5 days ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 09:59:53
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.11.89 (89.11.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:59:48.286023 2026] [security2:error] [pid 9607:tid 9607] [client 34.152.11.89:36740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "americancryonics.org"] [uri "/.git/config"] [unique_id "apAKlJ6jkQ9lEd8GE4JhEQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack