🇬🇧
openstrike.co.uk
2026-09-05 05:13:43
(1 day ago)
12 attacks on VC URLs:
GET /var/www/.git/config HTTP/1.1
Hacking
🇳🇱
e.fierstra
2026-09-05 00:45:21
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:02:07
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-04 21:21:14
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
interbiznw.com
2026-09-04 19:45:07
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
🇩🇪
webanyone
2026-09-04 18:02:19
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 14:15:03
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:54:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:54:07.924602 2026] [security2:error] [pid 20730:tid 20730] [client 34.27.33.180:35890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bienvenueplantation.cathrynn.com"] [uri "/src/.git/config"] [unique_id "aprNf1bjmSFKXmZTQhEBVAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇹
rooster
2026-09-04 13:00:50
(2 days ago)
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/www/.git/config" [Client 34.27. ...
show more
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/www/.git/config" [Client 34.27.33.180] [Length 150] [Gzip -] "crusader-worker/1.0" "-"
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/api/.git/config" [Client 34.27.33.180] [Length 150] [Gzip -] "crusader-worker/1.0" "-"
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/app/.git/config" [Client 34.27.33.180] [Length 150] [Gzip -] "crusader-worker/1.0" "-"
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/src/.git/config" [Client 34.27.33.180] [Length 150] [Gzip -] "crusader-worker/1.0" "-"
[04/Sep/2026:14:00:49 +0100] 404 - GET http homelab604.duckdns.org "/public/.git/config" [Client 34.27.33.180] [Length 150] [Gzip -] "crusader-worker/1.0" "-"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:26:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:26:17.316120 2026] [security2:error] [pid 9880:tid 9880] [client 34.27.33.180:42240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "projects.crep-psych.org"] [uri "/wordpress/.git/config"] [unique_id "apq46Qsp-D_wjK3mkyhh6gAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:52:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:52:27.339664 2026] [security2:error] [pid 6508:tid 6508] [client 34.27.33.180:53674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.celltechs.net"] [uri "/site/.git/config"] [unique_id "apqw-ytzSIgogXvZWyd1WAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 09:55:32
(2 days ago)
[04/Sep/2026:12:55:31 +0300] -- 34.27.33.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[04/Sep/2026:12:55:31 +0300] -- 34.27.33.180 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-04 08:12:29
(2 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 06:38:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:38:39.659418 2026] [security2:error] [pid 25653:tid 25653] [client 34.27.33.180:51824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archaiusmusic.com"] [uri "/site/.git/config"] [unique_id "appnb2PJRM1AuyeVgfhCCwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:58:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.27.33.180 (180.33.27.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:58:30.940559 2026] [security2:error] [pid 12636:tid 12636] [client 34.27.33.180:39856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customdesign.kemela.com"] [uri "/public/.git/config"] [unique_id "appeBppK1JryK1rIjlUZbQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack