🇧🇾
lns.bz
2026-09-06 09:58:39
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
mnsf
2026-09-06 05:05:43
(2 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:09:12
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:09:07.066374 2026] [security2:error] [pid 5645:tid 5645] [client 34.182.197.198:38598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||calveley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "calveley.com"] [uri "/db.sql"] [unique_id "apznYzjbmNBaUCrDXbgUswAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 02:19:11
(2 days ago)
Aggressive web scan
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 01:40:08
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:12:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:12:13.218127 2026] [security2:error] [pid 1957:tid 1957] [client 34.182.197.198:42210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hollorancompanies.com"] [uri "/.htaccess"] [unique_id "apy97TP61ybJ7UlO8xioqQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-05 23:06:55
(2 days ago)
[SunSep0601:06:50.3391412026][security2:error][pid2140833:tid2140942][client34.182.197.198:0]ModSecu ...
show more
[SunSep0601:06:50.3391412026][security2:error][pid2140833:tid2140942][client34.182.197.198:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"pulispina.ch\"][uri\"/site/.git/config\"][unique_id\"apygihqw0-mLY11n0b8sAQAAAMo\"]
show less
Port Scan
Brute-Force
Web App Attack
🇬🇧
Artelis
2026-09-05 22:18:59
(2 days ago)
34.182.197.198 - - [05/Sep/2026:22:18:58 +0000] "GET /api/.git/config HTTP/1.1" 404 146 "-" "crusade ...
show more
34.182.197.198 - - [05/Sep/2026:22:18:58 +0000] "GET /api/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /backend/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /src/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /app/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /www/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /public/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /html/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
34.182.197.198 - - [05/Sep/2026:22:18:59 +0000] "GET /wordpress/.git/config HTTP/1.1
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-05 09:03:01
(2 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 01:56:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:56:11.448166 2026] [security2:error] [pid 1909:tid 1909] [client 34.182.197.198:50214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jerryfeil.com"] [uri "/wordpress/.git/config"] [unique_id "apt2uwXdlv7F_aFSI4a4zAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:51:52
(3 days ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/src/.git/config | /.git/con ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/src/.git/config | /.git/config | /www/.git/config
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:20:45
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.197.198 (198.197.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:20:40.370968 2026] [security2:error] [pid 11584:tid 11584] [client 34.182.197.198:40390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.webdryer.com"] [uri "/site/.git/config"] [unique_id "aps2KN8UtUtkeqn_YZoUWwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:10:35
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-04 16:17:28
(3 days ago)
Fail2Ban: 2026/09/04 16:17:28 [info] 47#47: *11356 client sent no required SSL certificate while rea ...
show more
Fail2Ban: 2026/09/04 16:17:28 [info] 47#47: *11356 client sent no required SSL certificate while reading client request headers, client: 34.182.197.198, server: dash.ddns.schauwecker.eu, request: "GET /www/.git/config HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/09/04 16:17:28 [info] 42#42: *11357 client sent no required SSL certificate while reading client request headers, client: 34.182.197.198, server: dash.ddns.schauwecker.eu, request: "GET /site/.git/config HTTP/1.1", host: "dash.ddns.schauwecker.eu"
2026/09/04 16:17:28 [info] 45#45: *11359 client sent no required SSL certificate while reading client request headers, client: 34.182.197.198, server: dash.ddns.schauwecker.eu, request: "GET /wordpress/.git/config HTTP/1.1", host: "dash.ddns.schauwecker.eu"
show less
Hacking
🇺🇸
Charlesiv
2026-09-04 14:30:47
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /htdocs/.git/config
Timestamp: 2026-09-04T13:10:06Z
Ray ID: a35d3b832af57ed1
UA: crusader-worker/1.0
show less
Bad Web Bot