🇦🇺
2000cn.com.au
2026-09-04 22:28:53
(16 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 22:22:30
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:22:24.416068 2026] [security2:error] [pid 11181:tid 11181] [client 34.185.167.147:39432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roughexports.com"] [uri "/api/.git/config"] [unique_id "aptEoOW8kZbRb8QVf04hcgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:31:30
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:31:25.772718 2026] [security2:error] [pid 1277:tid 1277] [client 34.185.167.147:59592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.enselme.com"] [uri "/www/.git/config"] [unique_id "aps4raB6gVM5QRFXvAhx2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Operator873
2026-09-04 21:30:45
(1 hour ago)
2026/09/04 16:30:42 [error] 377378#0: *4132036 access forbidden by rule, client: 34.185.167.147, ser ...
show more
2026/09/04 16:30:42 [error] 377378#0: *4132036 access forbidden by rule, client: 34.185.167.147, server: [OBFUSCATED], request: "GET /html/.git/config HTTP/1.1", host: "mail.ntars.net"
2026/09/04 16:30:42 [error] 377378#0: *4132036 access forbidden by rule, client: 34.185.167.147, server: [OBFUSCATED], request: "GET /html/.git/config HTTP/1.1", host: "mail.ntars.net"
2026/09/04 16:30:42 [error] 377378#0: *4132037 access forbidden by rule, client: 34.185.167.147, server: [OBFUSCATED], request: "GET /src/.git/config HTTP/1.1", host: "mail.ntars.net"
2026/09/04 16:30:42 [error] 377378#0: *4132037 access forbidden by rule, client: 34.185.167.147, server: [OBFUSCATED], request: "GET /src/.git/config HTTP/1.1", host: "mail.ntars.net"
2026/09/04 16:30:42 [error] 377378#0: *4132038 access forbidden by rule, client: 34.185.167.147, server: [OBFUSCATED], request: "GET /site/.git/config HTTP/1.1", host: "mail.ntars.net"
...
show less
Brute-Force
Web App Attack
🇩🇪
Blexyel
2026-09-04 21:04:18
(1 hour ago)
34.185.167.147 - - [04/Sep/2026:23:04:18 +0200] "GET /src/.git/config HTTP/1.1" 404 120 "-" "crusade ...
show more
34.185.167.147 - - [04/Sep/2026:23:04:18 +0200] "GET /src/.git/config HTTP/1.1" 404 120 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-04 19:19:07
(3 hours ago)
[web.zebs.ch] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /wordpress/. ...
show more
[web.zebs.ch] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /wordpress/.git/config | /htdocs/.git/config
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:52:31
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:52:25.069280 2026] [security2:error] [pid 2326:tid 2326] [client 34.185.167.147:38516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.gabosoftware.com"] [uri "/.git/config"] [unique_id "apsTadNv0nCxZnlfgYAlXQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:35:43
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:35:39.950204 2026] [security2:error] [pid 25625:tid 25625] [client 34.185.167.147:55680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gerrytolentino.net"] [uri "/app/.git/config"] [unique_id "apsPexGy_IV9uxxPInzu3AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-04 17:20:54
(5 hours ago)
80,443
Brute-Force
SSH
🇩🇪
4server
2026-09-04 15:43:01
(7 hours ago)
[FriSep0417:42:57.0750152026][security2:error][pid355844:tid355925][client34.185.167.147:0]ModSecuri ...
show more
[FriSep0417:42:57.0750152026][security2:error][pid355844:tid355925][client34.185.167.147:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"elyon2.ch.136-243-54-122.cpanel.site\"][uri\"/www/.git/config\"][unique_id\"aprnAfVVmF1jJWTsDYeL7wAAAJQ\"]
show less
Port Scan
Brute-Force
Web App Attack
🇩🇪
SwinT
2026-09-04 15:00:08
(7 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇬🇧
consul.to
2026-09-04 14:49:04
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-04 12:54:48
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 09:04:10
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.167.147 (147.167.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:04:03.596186 2026] [security2:error] [pid 3697:tid 3697] [client 34.185.167.147:54346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guthrieclan.us"] [uri "/html/.git/config"] [unique_id "apqJg_dCEHkscvPohGUTZAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 06:04:45
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack