๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-24 08:41:41
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 07:15:55
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:15:49.421577 2026] [security2:error] [pid 21065:tid 21065] [client 34.20.202.229:59200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "darkstarsystems.net"] [uri "/html/.git/config"] [unique_id "arTOJfmZBTcJd4qKbtaOCgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 05:34:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:34:02.476500 2026] [security2:error] [pid 1855:tid 1855] [client 34.20.202.229:47324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customdatasolutions.net.pjvcds.com"] [uri "/backend/.git/config"] [unique_id "arS2Sr8qRpx4VDqtpf4tCQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 05:28:26
(10 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.20.202.229 - - [24/Sep/2026:07:28:21 +0200] "GET /html/.git/config HTTP/1.1" 301 6242 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-23 22:39:06
(16 hours ago)
common Web Exploits being scanned
Web App Attack
๐ง๐ท
radardatelecom
2026-09-23 22:23:08
(17 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:04:12
(17 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
GoodOldTOS
2026-09-23 21:51:44
(17 hours ago)
Bad keywords detected in request: /.git/config/.git
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 21:35:53
(18 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:19:42
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:19:35.251468 2026] [security2:error] [pid 5813:tid 5813] [client 34.20.202.229:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cloudex.link"] [uri "/html/.git/config"] [unique_id "arRCZ1ps82FOw7uJ8yfLvQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:41:18
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:41:13.050915 2026] [security2:error] [pid 21790:tid 21790] [client 34.20.202.229:43648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clayrivers.com"] [uri "/www/.git/config"] [unique_id "arQ5aSuFJqT_ksdPPpkriwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 20:06:01
(19 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:57:29
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.20.202.229 (229.202.20.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:57:26.214937 2026] [security2:error] [pid 31264:tid 31337] [client 34.20.202.229:56426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christina.abney.info"] [uri "/www/.git/config"] [unique_id "arQvJq4_dV1R2lfC1cYBsQAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
spot
2026-09-23 17:55:29
(21 hours ago)
34.20.202.229 - - [23/Sep/2026:18:55:24 +0100] "GET /www/.git/config HTTP/1.1" 404 4658 "-" "crusade ...
show more
34.20.202.229 - - [23/Sep/2026:18:55:24 +0100] "GET /www/.git/config HTTP/1.1" 404 4658 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking