Anonymous
2026-08-28 00:40:16
(6 days ago)
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | / ...
show more
[ns1.moussaspartners.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /app/.git/config | /backend/.git/config
show less
Hacking
Web App Attack
๐ฏ๐ต
Green_
2026-08-27 20:51:19
(6 days ago)
fail2ban pubweb-trap ban
Port Scan
Web App Attack
๐ฉ๐ช
netclix.gr
2026-08-27 18:23:40
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.179.143.107 (DE/Germany/107.143.179. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.179.143.107 (DE/Germany/107.143.179.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
IndigoRidge
2026-08-27 16:41:18
(6 days ago)
34.179.143.107 - - [27/Aug/2026:12:41:18 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "crusader-wo ...
show more
34.179.143.107 - - [27/Aug/2026:12:41:18 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.179.143.107 - - [27/Aug/2026:12:41:18 -0400] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.179.143.107 - - [27/Aug/2026:12:41:18 -0400] "GET /src/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:59:41
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:59:35.580900 2026] [security2:error] [pid 4334:tid 4334] [client 34.179.143.107:57960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.deviswijf.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "apAmp1k4dhn4K-ZrUdG_UAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:44:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:44:28.370643 2026] [security2:error] [pid 7864:tid 7864] [client 34.179.143.107:56822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cidv.net.globalweb123.com"] [uri "/www/.git/config"] [unique_id "apAjHN7DpJXcebVaEK0g7gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-27 11:18:23
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 12 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:17:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:17:40.127562 2026] [security2:error] [pid 28397:tid 28412] [client 34.179.143.107:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.magicdiscovery.com"] [uri "/www/.git/config"] [unique_id "apAc1JbYOYXqFhhpL4QOIQAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 10:58:56
(6 days ago)
cloudlinux2 fail2ban: 2026-08-27 12:53:45,017 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-27 12:53:45,017 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 27.0.221.168 - 2026-08-27 12:53:44cloudlinux2 fail2ban: 2026-08-27 12:53:51,960 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 91.193.232.169 - 2026-08-27 12:53:51cloudlinux2 fail2ban: 2026-08-27 12:53:47,569 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 91.193.232.169 - 2026-08-27 12:53:46cloudlinux2 fail2ban: 2026-08-27 12:53:59,449 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.179.143.107 - 2026-08-27 12:53:59cloudlinux2 fail2ban: 2026-08-27 12:53:59,490 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.179.143.107 - 2026-08-27 12:53:59cloudlinux2 fail2ban: 2026-08-27 12:53:59,468 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.179.143.107 - 2026-08-27 12:53:59cloudlinux2 fail2ban: 2026-08-27 12:53:59,460 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.179.143.107 - 2026-08-27 12
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 09:22:25
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:22:18.258367 2026] [security2:error] [pid 21841:tid 21841] [client 34.179.143.107:39230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.favorcakepaperco.com"] [uri "/www/.git/config"] [unique_id "apAByucYtqVkN417ToYhJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 08:53:44
(6 days ago)
by Attack Lagwatch(gw)
DDoS Attack
Web Spam
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:36:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:36:32.733483 2026] [security2:error] [pid 12152:tid 12152] [client 34.179.143.107:57060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nightowlprinting.com"] [uri "/site/.git/config"] [unique_id "ao_3EM7k_bpJ4oILPAoS5QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:09:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:09:16.924195 2026] [security2:error] [pid 20065:tid 20065] [client 34.179.143.107:40032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "julieknightbooks.com"] [uri "/www/.git/config"] [unique_id "ao-4bIUyf2F6YIkReM-n2gAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 03:29:14
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:15:21
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.143.107 (107.143.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:15:16.698336 2026] [security2:error] [pid 30852:tid 30880] [client 34.179.143.107:55966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalpartssolution.com"] [uri "/app/.git/config"] [unique_id "ao-PpF9TCBl4ZEK44eytMQAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack