🇩🇪
FD-IX
2026-09-04 14:13:36
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 13:40:03
(1 hour ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-04 10:12:41
(5 hours ago)
34.185.173.199 - - [04/Sep/2026:12:12:33 +0200] "GET /app/.git/config HTTP/1.1" 403 146 "-" "crusade ...
show more
34.185.173.199 - - [04/Sep/2026:12:12:33 +0200] "GET /app/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.185.173.199 - - [04/Sep/2026:12:12:33 +0200] "GET /public/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.185.173.199 - - [04/Sep/2026:12:12:33 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:11:16
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:11:10.242510 2026] [security2:error] [pid 10804:tid 11055] [client 34.185.173.199:40712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arrowsinthequiver.com"] [uri "/src/.git/config"] [unique_id "apqZPne6a7HOMWDEtBx08wAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-04 09:57:13
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:25:09
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:25:02.845438 2026] [security2:error] [pid 21876:tid 21876] [client 34.185.173.199:38642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calvaryadminservices.com"] [uri "/htdocs/.git/config"] [unique_id "apqAXmA3jSIHXuncwI6ytQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 07:35:41
(7 hours ago)
Repeated exploit attempts, for example: /htdocs/.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
Anonymous
2026-09-04 05:26:18
(9 hours ago)
T: f2b 404 5x
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:33:16
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:33:12.709485 2026] [security2:error] [pid 2732:tid 2732] [client 34.185.173.199:35366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adventiststoday.satanisdead.com"] [uri "/api/.git/config"] [unique_id "apof2NniDtrSIFjzghVLxwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
000rosiu
2026-09-04 01:29:59
(13 hours ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /html/.git/config | UA: crusader-worker/1.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇳🇴
jad-abuse
2026-09-04 00:12:39
(15 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 36 hits.
show less
Web App Attack
🇳🇱
Savvii
2026-09-04 00:06:26
(15 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-03 23:41:42
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:13:31
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.173.199 (199.173.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:13:22.819434 2026] [security2:error] [pid 18851:tid 18851] [client 34.185.173.199:59862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "summithost.com"] [uri "/htdocs/.git/config"] [unique_id "apnxArkF3Mi_8mv0vHzSAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 18:25:50
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking