๐น๐ผ
neithnet
2026-09-06 06:44:11
(4 weeks ago)
Malicious web scan
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-09-06 06:30:06
(4 weeks ago)
Repeated requests for suspicious nonexistent URLs, for example: /var/www/.git/config (HTTP/1.1 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /var/www/.git/config (HTTP/1.1 port 443, user agent: "crusader-worker/1.0")
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-09-06 06:30:06
(4 weeks ago)
Repeated exploit attempts, for example: /api/.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
๐ซ๐ท
dynamix
2026-09-06 05:34:08
(4 weeks ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 04:29:23
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:29:17.104038 2026] [security2:error] [pid 11491:tid 11491] [client 34.178.201.251:60572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.elgatocapa.com"] [uri "/backend/.git/config"] [unique_id "apzsHbPmQVTMDg1diOKyogAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 02:22:21
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:22:13.756505 2026] [security2:error] [pid 32041:tid 32041] [client 34.178.201.251:54228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "publications.flyingdodostudio.com"] [uri "/src/.git/config"] [unique_id "apzOVXkZKKc_36-_fDTxZgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-05 23:32:01
(1 month ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
javierin
2026-09-05 22:49:27
(1 month ago)
34.178.201.251 - monitor.javierin.com - - [05/Sep/2026:22:49:26 +0000] "GET /site/.git/config HTTP/1 ...
show more
34.178.201.251 - monitor.javierin.com - - [05/Sep/2026:22:49:26 +0000] "GET /site/.git/config HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
34.178.201.251 - monitor.javierin.com - - [05/Sep/2026:22:49:26 +0000] "GET /api/.git/config HTTP/1.1" 404 7362 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-05 21:35:30
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-05 20:53:57
(1 month ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-05 09:19:42
(1 month ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-stl2-14)
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-05 02:32:03
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:31:55.734069 2026] [security2:error] [pid 21040:tid 21040] [client 34.178.201.251:56942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.napavalleyaddress.com"] [uri "/var/www/.git/config"] [unique_id "apt_G1FB-Sd3DCQqq280iwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-04 22:38:37
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-04 22:05:07
(1 month ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 21:41:11
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.201.251 (251.201.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:41:06.385532 2026] [security2:error] [pid 3913:tid 3913] [client 34.178.201.251:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailgate.perl-photo.com"] [uri "/api/.git/config"] [unique_id "aps68hhWpSy4IV9aRHNJigAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack