๐บ๐ธ
TPI-Abuse
2026-09-02 06:05:07
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:05:00.101381 2026] [security2:error] [pid 15367:tid 15367] [client 34.181.166.2:43768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.instagenii.com"] [uri "/api/.git/config"] [unique_id "ape8jCsIAkYaVu-mgpEFbQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-09-02 05:28:17
(44 minutes ago)
Unauthorized connections HTTP 403
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:17:31
(55 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:17:24.975642 2026] [security2:error] [pid 10091:tid 10091] [client 34.181.166.2:40048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.blacktieokc.com"] [uri "/www/.git/config"] [unique_id "apexZHGbkN98PTp8VYvmMQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 04:44:58
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:44:54.555771 2026] [security2:error] [pid 6832:tid 6832] [client 34.181.166.2:41662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cpking.com"] [uri "/www/.git/config"] [unique_id "apepxkPyk__MjusMYetk3wAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-09-02 03:11:20
(3 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 5): Restricted File Access Attempt;
Web App Attack
Anonymous
2026-09-02 00:40:02
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฌ๐ง
[email protected]
2026-09-02 00:26:56
(5 hours ago)
34.181.166.2 - - [02/Sep/2026:00:26:56 +0000] "GET /src/.git/config HTTP/1.1" 404 329 "-" "crusader- ...
show more
34.181.166.2 - - [02/Sep/2026:00:26:56 +0000] "GET /src/.git/config HTTP/1.1" 404 329 "-" "crusader-worker/1.0"
34.181.166.2 - - [02/Sep/2026:00:26:56 +0000] "GET /backend/.git/config HTTP/1.1" 404 329 "-" "crusader-worker/1.0"
34.181.166.2 - - [02/Sep/2026:00:26:56 +0000] "GET /api/.git/config HTTP/1.1" 404 329 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-02 00:01:35
(6 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
Anonymous
2026-09-01 23:20:03
(6 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:40:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:40:10.629101 2026] [security2:error] [pid 20790:tid 20798] [client 34.181.166.2:33292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "triestemagica.org"] [uri "/htdocs/.git/config"] [unique_id "apdUSqv2Np-HaRMveFFjPgAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 18:45:33
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
loveprod
2026-09-01 16:07:40
(14 hours ago)
34.181.166.2 - - [01/Sep/2026:19:07:39 +0300] "GET /.git/config HTTP/2.0" 403 553 "-" "crusader-work ...
show more
34.181.166.2 - - [01/Sep/2026:19:07:39 +0300] "GET /.git/config HTTP/2.0" 403 553 "-" "crusader-worker/1.0"
34.181.166.2 - - [01/Sep/2026:19:07:39 +0300] "GET /public/.git/config HTTP/2.0" 404 56742 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-01 10:29:35
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:29:26.924382 2026] [security2:error] [pid 18965:tid 18965] [client 34.181.166.2:39268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randlephoto.gregorii.com"] [uri "/app/.git/config"] [unique_id "apapBrfKPCDk10uU20vIBQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-09-01 10:22:26
(19 hours ago)
[REDACTED] 34.181.166.2 - - [01/Sep/2026:12:22:25 +0200] "GET /.git/config HTTP/1.1" 404 4616 "-" "c ...
show more
[REDACTED] 34.181.166.2 - - [01/Sep/2026:12:22:25 +0200] "GET /.git/config HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:53:20
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.166.2 (2.166.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:53:15.122663 2026] [security2:error] [pid 23434:tid 23434] [client 34.181.166.2:53496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.radtraininginc.com"] [uri "/.git/config"] [unique_id "apagi_uJoaC01HNjXTsJTQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack