🇧🇾
lns.bz
2026-09-06 09:00:23
(6 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
Michel Wijnberg
2026-09-06 06:16:27
(9 hours ago)
34.180.32.4 - - [06/Sep/2026:06:16:26 +0000] "GET /htdocs/.git/config HTTP/1.1" 404 146 "-" "crusade ...
show more
34.180.32.4 - - [06/Sep/2026:06:16:26 +0000] "GET /htdocs/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 05:41:50
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
IndigoRidge
2026-09-06 05:03:50
(10 hours ago)
34.180.32.4 - - [06/Sep/2026:01:03:49 -0400] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-w ...
show more
34.180.32.4 - - [06/Sep/2026:01:03:49 -0400] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.180.32.4 - - [06/Sep/2026:01:03:49 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.180.32.4 - - [06/Sep/2026:01:03:49 -0400] "GET /src/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-06 04:38:55
(10 hours ago)
Web scanner: GET /public/.git/config
Web App Attack
Hacking
🇳🇴
jad-abuse
2026-09-06 04:34:10
(10 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 36 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:17:23
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.180.32.4 (4.32.180.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.32.4 (4.32.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:17:15.004874 2026] [security2:error] [pid 28990:tid 29004] [client 34.180.32.4:33250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "biblewriter.com"] [uri "/src/.git/config"] [unique_id "apzbO4nbmbWWpEL5qYYV1wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Charlesiv
2026-09-06 02:46:26
(12 hours ago)
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from IN.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /phpinfo.php
Timestamp: 2026-09-06T01:21:50Z
Ray ID: a369a8c29ca93aab
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-09-06 01:34:00
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-05 23:02:06
(16 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:02:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.180.32.4 (4.32.180.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.32.4 (4.32.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:02:04.348833 2026] [security2:error] [pid 30267:tid 30267] [client 34.180.32.4:35388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deborbonfoundation.org"] [uri "/src/.git/config"] [unique_id "apyRXKZpMaE9DJmdwnY1FgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 21:18:29
(18 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇳🇱
Cloud86 B.V.
2026-09-05 21:15:02
(18 hours ago)
categories: DDoS Attack
DDoS Attack
Anonymous
2026-09-04 21:26:31
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking