🇩🇪
FeG Deutschland
2026-08-27 18:42:05
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:04:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:04:27.331090 2026] [security2:error] [pid 30773:tid 30773] [client 34.181.230.63:44252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yukitex.net"] [uri "/wordpress/.git/config"] [unique_id "apB8K5VaDdlganGwG-Va3gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pscriptos
2026-08-27 18:01:13
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-27 17:30:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:30:17.355348 2026] [security2:error] [pid 10637:tid 10637] [client 34.181.230.63:45298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.105kqv.com"] [uri "/site/.git/config"] [unique_id "apB0KZuLj_JrxwZ3D-nAJQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 15:32:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:32:38.219992 2026] [security2:error] [pid 24282:tid 24282] [client 34.181.230.63:49570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jsolanogranite.com"] [uri "/api/.git/config"] [unique_id "apBYloSXI2Xe4_pCo6g4sgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 15:22:27
(2 days ago)
GET /.git/config HTTP/1.1
...
Web App Attack
🇷🇴
iulianh
2026-08-27 14:16:57
(2 days ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-27 13:46:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:46:02.793365 2026] [security2:error] [pid 5783:tid 5783] [client 34.181.230.63:41560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oakglenhouse.com.benchmarkbcs.com"] [uri "/www/.git/config"] [unique_id "apA_msw8bNWWGPmjwJZBbQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 13:08:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:08:43.079840 2026] [security2:error] [pid 27158:tid 27158] [client 34.181.230.63:32896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nuevo.allcostaricarentals.com"] [uri "/app/.git/config"] [unique_id "apA227T5_JMbdGt-NFGTfwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 12:40:02
(2 days ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 12:15:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.230.63 (63.230.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:15:15.908441 2026] [security2:error] [pid 9647:tid 9647] [client 34.181.230.63:39190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "towlefarmcommunity.org"] [uri "/html/.git/config"] [unique_id "apAqU8IM4oo6nPL2qH3x4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-27 12:08:36
(2 days ago)
[ThuAug2714:08:29.7121992026][security2:error][pid1132950:tid1133013][client34.181.230.63:0]ModSecur ...
show more
[ThuAug2714:08:29.7121992026][security2:error][pid1132950:tid1133013][client34.181.230.63:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"sisuconsulting.net.136-243-54-122.cpanel.site\"][uri\"/public/.git/config\"][unique_id\"apAovd3CVTdjrGZW4htSRQAAAIE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-08-27 12:06:06
(2 days ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
🇫🇷
Stara
2026-08-27 10:38:26
(2 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack