π³π±
i-turnradio.nl
2026-09-01 04:15:10
(1 day ago)
2026-09-01 @ 06:15:09 (CET) ~ Blocked for trying to access: /src/.git/config
Web App Attack
πΊπΈ
IndigoRidge
2026-09-01 04:12:18
(1 day ago)
34.27.195.228 - - [01/Sep/2026:00:12:15 -0400] "GET /.git/config HTTP/1.1" 302 4863 "-" "crusader-wo ...
show more
34.27.195.228 - - [01/Sep/2026:00:12:15 -0400] "GET /.git/config HTTP/1.1" 302 4863 "-" "crusader-worker/1.0"
34.27.195.228 - - [01/Sep/2026:00:12:17 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.27.195.228 - - [01/Sep/2026:00:12:15 -0400] "GET /api/.git/config HTTP/1.1" 302 4869 "-" "crusader-worker/1.0"
...
show less
Web App Attack
π¬π§
Aetherweb Ark
2026-09-01 04:12:07
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.27.195.228 (US/United States/228.195.27.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.27.195.228 (US/United States/228.195.27.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:06:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:06:46.465502 2026] [security2:error] [pid 6756:tid 6756] [client 34.27.195.228:42352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cacs.me"] [uri "/.git/config"] [unique_id "apZPVhwyNnvtE01F_7oAzwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:41:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:41:23.499070 2026] [security2:error] [pid 11709:tid 11709] [client 34.27.195.228:59220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "martinka.martinka.org"] [uri "/htdocs/.git/config"] [unique_id "apZJY37l62PtWfn2ydvHQQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:18:02
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.27.195.228 (228.195.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.27.195.228 (228.195.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:17:58.094276 2026] [security2:error] [pid 18402:tid 18402] [client 34.27.195.228:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.abdulhameeds.art|F|2"] [data ".php.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.abdulhameeds.art"] [uri "/api/phpinfo.php.old"] [unique_id "apZD5hBKblCsVEBrSRncuwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 02:42:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:42:17.100850 2026] [security2:error] [pid 31526:tid 31526] [client 34.27.195.228:46644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.microbooty.com"] [uri "/public/.git/config"] [unique_id "apY7icqNV1w4_VE-Io3fAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Philister11
2026-09-01 01:56:46
(2 days ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
π³π±
Savvii
2026-09-01 01:50:58
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-08-31 16:31:52
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-08-30 00:13:37
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-29 23:42:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.195.228 (228.195.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:42:29.976698 2026] [security2:error] [pid 4833:tid 4833] [client 34.27.195.228:40098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afdfurniture.com"] [uri "/htdocs/.git/config"] [unique_id "apNuZccjD3CZB0iTNYbLlgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-08-29 21:58:49
(4 days ago)
[30/Aug/2026:00:58:49 +0300] -- 34.27.195.228 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[30/Aug/2026:00:58:49 +0300] -- 34.27.195.228 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-28 22:01:56
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
πΊπΈ
IndigoRidge
2026-08-27 23:10:49
(6 days ago)
34.27.195.228 - - [27/Aug/2026:19:10:49 -0400] "GET /backend/.git/config HTTP/1.1" 301 162 "-" "crus ...
show more
34.27.195.228 - - [27/Aug/2026:19:10:49 -0400] "GET /backend/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.27.195.228 - - [27/Aug/2026:19:10:49 -0400] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.27.195.228 - - [27/Aug/2026:19:10:49 -0400] "GET /html/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack