๐ฎ๐น
ciccio diddo
2026-09-24 05:18:40
(16 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:35:58
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:35:53.127778 2026] [security2:error] [pid 22299:tid 22299] [client 34.40.248.226:59178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.scc1.us"] [uri "/api/.git/config"] [unique_id "arSMibYiWMb33U5pmlBwvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:59:08
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:59:02.205750 2026] [security2:error] [pid 31158:tid 31158] [client 34.40.248.226:49122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.alphacom.us"] [uri "/site/.git/config"] [unique_id "arRnxkX29VysapTPfjSAAQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 22:50:37
(22 hours ago)
[24/Sep/2026:01:50:37 +0300] -- 34.40.248.226 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[24/Sep/2026:01:50:37 +0300] -- 34.40.248.226 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:16:18
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:16:13.443718 2026] [security2:error] [pid 475:tid 475] [client 34.40.248.226:52992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cointraptions.com"] [uri "/api/.git/config"] [unique_id "arRPraviTXoaqygPJD-MbQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:59:53
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:59:48.596708 2026] [security2:error] [pid 1720:tid 1720] [client 34.40.248.226:44390] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "chuckwagon.org"] [uri "/htdocs/.git/config"] [unique_id "arQvtEIHsJHjzEx2H6hn1gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-23 16:47:33
(1 day ago)
[Wed Sep 23 18:47:32.933989 2026] [core:info] [pid 1540324:tid 126351528933056] [client 34.40.248.22 ...
show more
[Wed Sep 23 18:47:32.933989 2026] [core:info] [pid 1540324:tid 126351528933056] [client 34.40.248.226:56918] AH00128: File does not exist: /var/www/franvallejo/api/.git/config
[Wed Sep 23 18:47:32.934289 2026] [core:info] [pid 1540326:tid 126352057411264] [client 34.40.248.226:56946] AH00128: File does not exist: /var/www/franvallejo/src/.git/config
[Wed Sep 23 18:47:32.940452 2026] [core:info] [pid 1540326:tid 126351621220032] [client 34.40.248.226:56976] AH00128: File does not exist: /var/www/franvallejo/backend/.git/config
[Wed Sep 23 18:47:32.940452 2026] [core:info] [pid 1540326:tid 126352233592512] [client 34.40.248.226:57008] AH00128: File does not exist: /var/www/franvallejo/html/.git/config
[Wed Sep 23 18:47:32.940673 2026] [core:info] [pid 1540326:tid 126352065803968] [client 34.40.248.226:56962] AH00128: File does not exist: /var/www/franvallejo/app/.git/config
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-23 15:50:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:50:12.136686 2026] [security2:error] [pid 2910:tid 2910] [client 34.40.248.226:51742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bvi-boat-registration.com"] [uri "/app/.git/config"] [unique_id "arP1NAgdQVrhKvxmLvVwiwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:40:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:39:59.935674 2026] [security2:error] [pid 11415:tid 11415] [client 34.40.248.226:48396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "braleygroup.com"] [uri "/src/.git/config"] [unique_id "arPkv9mxJdBNDbdmeiLgcwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 13:59:10
(1 day ago)
[23/Sep/2026:15:59:10 +0200] 179017195034.157863 34.40.248.226 0 217.154.7.177 443
[23/Sep/2026:15:5 ...
show more
[23/Sep/2026:15:59:10 +0200] 179017195034.157863 34.40.248.226 0 217.154.7.177 443
[23/Sep/2026:15:59:10 +0200] 179017195022.623328 34.40.248.226 0 217.154.7.177 443
[23/Sep/2026:15:59:10 +0200] 179017195097.743090 34.40.248.226 0 217.154.7.177 443
[23/Sep/2026:15:59:10 +0200] 179017195037.117368 34.40.248.226 0 217.154.7.177 443
[23/Sep/2026:15:59:10 +0200] 179017195094.912596 34.40.248.226 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 13:55:19
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:03:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.248.226 (226.248.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:03:48.857459 2026] [security2:error] [pid 13430:tid 13430] [client 34.40.248.226:37474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blisseventboutique.kawkacevents.com"] [uri "/public/.git/config"] [unique_id "arPONLnMADvnrIAhxuSpvwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 11:05:28
(1 day ago)
[livebd] Web exploit scanning: 5 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[livebd] Web exploit scanning: 5 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.40.248.226 - - [23/Sep/2026:13:05:22 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 7866 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:13:05:22 +0200] "GET /html/.git/config HTTP/1.1" 404 7866 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:13:05:22 +0200] "GET /site/.git/config HTTP/1.1" 404 7866 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:13:05:22 +0200] "GET /.git/config HTTP/1.1" 404 7866 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:13:05:22 +0200] "GET /app/.git/config HTTP/1.1" 404 7866 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-23 11:03:08
(1 day ago)
[WedSep2313:03:04.7287782026][security2:error][pid599628:tid600157][client34.40.248.226:0]ModSecurit ...
show more
[WedSep2313:03:04.7287782026][security2:error][pid599628:tid600157][client34.40.248.226:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"behindthemoon.ch\"][uri\"/src/.git/config\"][unique_id\"arOx6Idjs7AEaYcvuzuQtgAAAAc\"]
show less
Hacking
Web App Attack
Anonymous
2026-09-23 10:01:17
(1 day ago)
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader ...
show more
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /app/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.40.248.226 - - [23/Sep/2026:12:01:16 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "
...
show less
Bad Web Bot
Web App Attack