🇺🇸
TPI-Abuse
2026-09-06 01:22:00
(37 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:21:54.450526 2026] [security2:error] [pid 4094055:tid 4094064] [client 34.21.176.153:59554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interactiveintermediaries.com.richardleeweatherman.com"] [uri "/htdocs/.git/config"] [unique_id "apzAMq6cqs6FLYTdRl_NVAAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-06 00:58:34
(1 hour ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:18:58
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:18:52.199702 2026] [security2:error] [pid 336:tid 336] [client 34.21.176.153:44690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiointernational.net"] [uri "/app/.git/config"] [unique_id "apyjXL_AcKf5w1H6S_FUQgAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-05 09:39:03
(16 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:32:34
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:32:27.621402 2026] [security2:error] [pid 11897:tid 11897] [client 34.21.176.153:40020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.crescentcitycafe.org"] [uri "/app/.git/config"] [unique_id "apt_O4aDkxoqP0O4SJkLyQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-05 02:21:02
(23 hours ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-04 19:16:26
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:16:22.140874 2026] [security2:error] [pid 7975:tid 7975] [client 34.21.176.153:41696] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "tgto.cescfoundation.org"] [uri "/www/.git/config"] [unique_id "apsZBvEGHaRIxx2M45gRBQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 19:01:03
(1 day ago)
34.21.176.153 - - [04/Sep/2026:21:00:56 +0200] "GET /app/.git/config HTTP/1.1" 403 146 "-" "crusader ...
show more
34.21.176.153 - - [04/Sep/2026:21:00:56 +0200] "GET /app/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.21.176.153 - - [04/Sep/2026:21:00:56 +0200] "GET /public/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.21.176.153 - - [04/Sep/2026:21:00:56 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
raph
2026-09-04 16:45:32
(1 day ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:58:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:58:27.290885 2026] [security2:error] [pid 1026332:tid 1026332] [client 34.21.176.153:39200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nadepot.nodepot.com"] [uri "/htdocs/.git/config"] [unique_id "aprqo0m2luK17kK69d6XwQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
FEWA
2026-09-04 12:35:29
(1 day ago)
Fail2Ban Ban Triggered
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 12:16:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.21.176.153 (153.176.21.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:16:44.050978 2026] [security2:error] [pid 15055:tid 15055] [client 34.21.176.153:58570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ran101.com"] [uri "/.git/config"] [unique_id "apq2rGzAf5K8Im1HjnomlAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 10:19:36
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-04 07:25:33
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 06:34:35
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /var/www/.git/config (+11 more) | 2026-09-04 06:34 UTC
show less
Hacking
Web App Attack