๐ช๐ธ
masterguru
2026-08-29 10:08:56
(3 days ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ฎ๐น
madaello
2026-08-29 09:25:48
(3 days ago)
34.175.161.81 - - [29/Aug/2026:11:25:48 +0200] "GET /backend/.git/config HTTP/1.1" 301 4744 "-" "cru ...
show more
34.175.161.81 - - [29/Aug/2026:11:25:48 +0200] "GET /backend/.git/config HTTP/1.1" 301 4744 "-" "crusader-worker/1.0"
34.175.161.81 - - [29/Aug/2026:11:25:48 +0200] "GET /app/.git/config HTTP/1.1" 301 4738 "-" "crusader-worker/1.0"
34.175.161.81 - - [29/Aug/2026:11:25:48 +0200] "GET /.git/config HTTP/1.1" 301 4729 "-" "crusader-worker/1.0"
34.175.161.81 - - [29/Aug/2026:11:25:48 +0200] "GET /src/.git/config HTTP/1.1" 301 4736 "-" "crusader-worker/1.0"
...
show less
Hacking
๐จ๐ญ
m_vlasov
2026-08-29 06:29:54
(3 days ago)
SSH/Telnet honeypot: 0 login attempts, 0 sessions, 0 shell commands.
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-29 05:46:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 01:46:51.516657 2026] [security2:error] [pid 29874:tid 29874] [client 34.175.161.81:55236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trasimeno.montepulciano.org"] [uri "/www/.git/config"] [unique_id "apJySw15ycNfrngvOfAvHAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:54:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:54:48.555360 2026] [security2:error] [pid 6846:tid 6846] [client 34.175.161.81:41290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.skylinepools.com"] [uri "/site/.git/config"] [unique_id "apJmGFaLch_qWmj-VpCjnAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-29 04:04:22
(3 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ซ๐ท
masterguru
2026-08-29 03:34:23
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:34:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:34:07.431938 2026] [security2:error] [pid 22768:tid 22768] [client 34.175.161.81:41204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.railfairofseo.com.powerlinemultimedia.net"] [uri "/backend/.git/config"] [unique_id "apI3D-Hf4wKEynfY-En1tQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 23:17:55
(4 days ago)
[29/Aug/2026:02:17:55 +0300] -- 34.175.161.81 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[29/Aug/2026:02:17:55 +0300] -- 34.175.161.81 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-28 19:51:17
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-28 14:45:15
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 14:05:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.161.81 (81.161.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 10:05:46.012721 2026] [security2:error] [pid 25518:tid 25518] [client 34.175.161.81:37812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "azpinklimos.com"] [uri "/.git/config"] [unique_id "apGVutp1jZjKKS3poNSVggAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-28 13:42:24
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฎ๐น
ivanbiagi7
2026-08-28 12:20:26
(4 days ago)
Wazuh detected repeated HTTP client errors consistent with automated web probing. Wazuh rule=31151.
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 12:16:46
(4 days ago)
Web attack/malicious scanning detected
Web App Attack