๐ฉ๐ช
klaus_ph
2026-09-26 12:29:21
(9 hours ago)
2026-09-25 16:20:00,879 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.39.196.23
...
Bad Web Bot
๐บ๐ธ
craudiovizai
2026-09-24 12:30:32
(2 days ago)
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config, /site/. ...
show more
Automated honeypot detection. blocked ip against a Next.js application. Paths: /.git/config, /site/.git/config. Blocked at the edge.
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-24 08:49:55
(2 days ago)
[ti-07al] Web exploit scanning: 7 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 7 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.39.196.23 - - [24/Sep/2026:10:49:53 +0200] "GET /app/.git/config HTTP/1.1" 403 5787 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:56:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:56:37.584600 2026] [security2:error] [pid 19664:tid 19664] [client 34.39.196.23:52026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davisllp.com"] [uri "/htdocs/.git/config"] [unique_id "arTXtaApA6pIDdwLEB2rlQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 07:53:54
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:12:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:12:30.242488 2026] [security2:error] [pid 15119:tid 15119] [client 34.39.196.23:52112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danzadance.danzadance.org"] [uri "/src/.git/config"] [unique_id "arTNXmNqJn5FFPKq4IhYcQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:26:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:25:54.156884 2026] [security2:error] [pid 1490:tid 1490] [client 34.39.196.23:47548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "d365geek.com"] [uri "/wordpress/.git/config"] [unique_id "arTCctyMzchHVId8btiCKwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 05:50:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:50:16.436022 2026] [security2:error] [pid 14600:tid 14600] [client 34.39.196.23:54578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cycontechnology.com"] [uri "/app/.git/config"] [unique_id "arS6GANdpyVGBcQt_1r-ugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-24 04:45:03
(2 days ago)
[24/Sep/2026:06:45:02.350316 +0200] arSqzmHO4HwXlLRf7wb-jAAAAAU 34.39.196.23 49990 127.0.0.1 7081
[2 ...
show more
[24/Sep/2026:06:45:02.350316 +0200] arSqzmHO4HwXlLRf7wb-jAAAAAU 34.39.196.23 49990 127.0.0.1 7081
[24/Sep/2026:06:45:02.352926 +0200] arSqzhlEXhU_wvZESDhGEQAAAAI 34.39.196.23 49996 127.0.0.1 7081
[24/Sep/2026:06:45:02.358623 +0200] arSqzj0IokklFDyj4p0SngAAAAc 34.39.196.23 50018 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:30:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.196.23 (23.196.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:30:50.077978 2026] [security2:error] [pid 23900:tid 23900] [client 34.39.196.23:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.wiszen.org"] [uri "/api/.git/config"] [unique_id "arR9SnLiR60Yy9C0zvNbsQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 00:25:05
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
arnisolutions
2026-09-23 23:55:25
(2 days ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-23 and 2026-09-23 (UTC). Sample request: GET /html/.git/config HTTP/1.1
show less
Web App Attack
Hacking
๐บ๐ธ
Gabriel Camargo
2026-09-23 22:11:19
(3 days ago)
34.39.196.23 - - [23/Sep/2026:17:11:18 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusader- ...
show more
34.39.196.23 - - [23/Sep/2026:17:11:18 -0500] "GET /api/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.39.196.23 - - [23/Sep/2026:17:11:18 -0500] "GET /backend/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.39.196.23 - - [23/Sep/2026:17:11:18 -0500] "GET /src/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
๐ฉ๐ช
XICTRON
2026-09-23 21:15:06
(3 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack