🇫🇷
Catalin Negru
2026-09-09 04:40:53
(1 day ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇫🇷
dynamix
2026-09-06 05:40:54
(4 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:09:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:09:03.890075 2026] [security2:error] [pid 18042:tid 18062] [client 34.159.205.141:59352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darrylrichards.com"] [uri "/app/.git/config"] [unique_id "apz1b_BEH8oKGMOdva9WJQAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:54:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:53:54.898670 2026] [security2:error] [pid 12882:tid 12882] [client 34.159.205.141:45080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "threewild.com"] [uri "/public/.git/config"] [unique_id "apzHsnctEoaX2zLMEf4ruAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gws-hostmaster
2026-09-05 21:17:24
(5 days ago)
ModSecurity OWASP CRS (Anomaly Score: 5): Restricted File Access Attempt;
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:12:21
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:12:13.814131 2026] [security2:error] [pid 18097:tid 18097] [client 34.159.205.141:41346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.baystreet.news"] [uri "/backend/.git/config"] [unique_id "apyFra6SAQ45ParYSUer_gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Dennis
2026-09-05 08:09:39
(5 days ago)
34.159.205.141 has been banned for triggering http-sensitive-files (5 events over 6.752621ms).
Brute-Force
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-05 02:29:03
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.159.205.141 (DE/Germany/141.205.159. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.159.205.141 (DE/Germany/141.205.159.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
ddobko
2026-09-05 01:40:41
(5 days ago)
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-04 22:19:45
(6 days ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:53:37
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:53:29.861218 2026] [security2:error] [pid 25072:tid 25072] [client 34.159.205.141:47940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.epicureankids.com"] [uri "/var/www/.git/config"] [unique_id "aps92eWCF6nQ_r_2zTc0cAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-04 21:25:28
(6 days ago)
2026/09/04 21:25:26 [error] 754820#754820: *557230110 access forbidden by rule, client: 34.159.205.1 ...
show more
2026/09/04 21:25:26 [error] 754820#754820: *557230110 access forbidden by rule, client: 34.159.205.141, server: fn.binixo.es, request: "GET /www/.git/config HTTP/2.0", host: "mailgate.fastcredit.net.ua"
2026/09/04 21:25:26 [error] 754822#754822: *557230111 access forbidden by rule, client: 34.159.205.141, server: fn.binixo.es, request: "GET /backend/.git/config HTTP/2.0", host: "mailgate.fastcredit.net.ua"
2026/09/04 21:25:26 [error] 754822#754822: *557230112 access forbidden by rule, client: 34.159.205.141, server: fn.binixo.es, request: "GET /wordpress/.git/config HTTP/2.0", host: "mailgate.fastcredit.net.ua"
...
show less
Web App Attack
🇫🇷
Catalin Negru
2026-09-04 21:03:57
(6 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
Gabriel Camargo
2026-09-04 19:11:45
(6 days ago)
34.159.205.141 - - [04/Sep/2026:14:11:45 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-wo ...
show more
34.159.205.141 - - [04/Sep/2026:14:11:45 -0500] "GET /.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.159.205.141 - - [04/Sep/2026:14:11:45 -0500] "GET /src/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.159.205.141 - - [04/Sep/2026:14:11:45 -0500] "GET /app/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 18:58:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.205.141 (141.205.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:58:52.887007 2026] [security2:error] [pid 4827:tid 4827] [client 34.159.205.141:58792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.picticon.com"] [uri "/src/.git/config"] [unique_id "apsU7FNOp7B7jedaTo5cAgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack