๐ง๐ฌ
Stoyko Stoykov
2026-09-02 05:11:52
(2 hours ago)
34.32.6.26 - - [02/Sep/2026:08:11:51 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; ...
show more
34.32.6.26 - - [02/Sep/2026:08:11:51 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ซ๐ท
sthoyer.de
2026-09-02 03:28:11
(4 hours ago)
34.32.6.26 - - [02/Sep/2026:05:28:10 +0200] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Ma ...
show more
34.32.6.26 - - [02/Sep/2026:05:28:10 +0200] "GET /.git/config HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.6.26 - - [02/Sep/2026:05:28:10 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.6.26 - - [02/Sep/2026:05:28:10 +0200] "GET /.env.local HTTP/1.1" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-02 02:13:01
(5 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-09-02 01:29:05
(6 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.32.6.26 (DE/Germany/26.6.32.34.bc.googleuser ...
show more
(mod_security) mod_security (id:949110) triggered by 34.32.6.26 (DE/Germany/26.6.32.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 01:17:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:17:15.694297 2026] [security2:error] [pid 4781:tid 4781] [client 34.32.6.26:38166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.starwarsrules.com"] [uri "/.git/config"] [unique_id "apd5GxPiNB3sw023aS_U7QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-02 01:07:58
(6 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-02 00:39:57
(7 hours ago)
Malware host detected by rbl.malware.expert. RBL lookup of 26.6.32.34.rbl.malware.expert succeeded a ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 26.6.32.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 00:19:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:18:59.512530 2026] [security2:error] [pid 28903:tid 28903] [client 34.32.6.26:56352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stananddana.com"] [uri "/.git/config"] [unique_id "apdrc3yF7y_VQ-n9rkD0PwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
miriks
2026-09-01 23:56:37
(7 hours ago)
Automated scan detected: GET /.git/config โ UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Automated scan detected: GET /.git/config โ UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
Anonymous
2026-09-01 23:54:42
(7 hours ago)
[ns31.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.e ...
show more
[ns31.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ต๐ฑ
srebrakowski.com
2026-09-01 20:57:54
(10 hours ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 19:58:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 15:58:04.841336 2026] [security2:error] [pid 4250:tid 4250] [client 34.32.6.26:35370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.sprayrealty.com"] [uri "/.git/config"] [unique_id "apcuTBGSyItC9NJyVdwB1QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 19:38:38
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-01 19:21:39
(12 hours ago)
Trapped by Fail2Ban: Too many login failures from 34.32.6.26
Brute-Force
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 18:31:12
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.6.26 (26.6.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:31:08.861206 2026] [security2:error] [pid 14209:tid 14209] [client 34.32.6.26:50320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.spidersbox.com"] [uri "/.git/config"] [unique_id "apcZ7FyTYeugpUNvg_SD1wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack