๐ฉ๐ช
raph
2026-09-02 14:47:56
(23 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 14:11:49
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-02 08:06:06
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-stl2-17)
Hacking
Web App Attack
๐ฉ๐ช
marcel-knorr.de
2026-09-02 06:48:06
(1 day ago)
[MK-Root1] Blocked by UFW
Brute-Force
Port Scan
๐ฉ๐ช
pigro
2026-09-02 05:50:57
(1 day ago)
34.181.157.196 - - [02/Sep/2026:07:50:57 +0200] "GET /api/.git/config HTTP/1.1" 301 5 "-" "crusader- ...
show more
34.181.157.196 - - [02/Sep/2026:07:50:57 +0200] "GET /api/.git/config HTTP/1.1" 301 5 "-" "crusader-worker/1.0"
34.181.157.196 - - [02/Sep/2026:07:50:57 +0200] "GET /backend/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-02 05:44:04
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 05:23:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:23:05.190148 2026] [security2:error] [pid 32183:tid 32183] [client 34.181.157.196:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hcoahawaii.org"] [uri "/src/.git/config"] [unique_id "apeyuT1m8hALu4L9HLjWFwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 05:14:42
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
debestelapp
2026-09-02 03:30:10
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 03:22:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:22:44.269270 2026] [security2:error] [pid 30728:tid 30728] [client 34.181.157.196:39968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dimitri.daras.name"] [uri "/.git/config"] [unique_id "apeWhH3Z8af-umv7NMU1HwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-02 00:44:06
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 00:43:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:43:45.368607 2026] [security2:error] [pid 1807:tid 1807] [client 34.181.157.196:45784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.emhelectric.com"] [uri "/.git/config"] [unique_id "apdxQR6EXqTFvCtyDajqjwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 20:58:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:58:14.203897 2026] [security2:error] [pid 29837:tid 29837] [client 34.181.157.196:46336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnphilos.bridgital.com"] [uri "/html/.git/config"] [unique_id "apc8ZsZmDj8tGu2eXQGIKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:15:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.157.196 (196.157.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:15:35.647337 2026] [security2:error] [pid 24221:tid 24221] [client 34.181.157.196:58956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.groz.net"] [uri "/wordpress/.git/config"] [unique_id "apcWR1pq-R8_nrShJfug-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 12:39:39
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack