🇧🇾
lns.bz
2026-09-05 07:15:55
(3 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
loveprod
2026-09-04 14:48:14
(19 hours ago)
34.47.72.227 - - [04/Sep/2026:17:48:13 +0300] "GET /site/.git/config HTTP/2.0" 404 57054 "-" "crusad ...
show more
34.47.72.227 - - [04/Sep/2026:17:48:13 +0300] "GET /site/.git/config HTTP/2.0" 404 57054 "-" "crusader-worker/1.0"
34.47.72.227 - - [04/Sep/2026:17:48:13 +0300] "GET /wordpress/.git/config HTTP/2.0" 404 56744 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
🇸🇪
SkyDancer
2026-09-04 10:39:02
(1 day ago)
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by ...
show more
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai via interface.
show less
Hacking
Brute-Force
SSH
🇸🇪
SkyDancer
2026-09-04 08:20:05
(1 day ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 05:31:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:31:49.739475 2026] [security2:error] [pid 2198740:tid 2198803] [client 34.47.72.227:39136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.grupojdg.com"] [uri "/html/.git/config"] [unique_id "appXxTsF5zHBuNPdRVEOtwAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 04:55:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇨🇦
polycoda
2026-09-04 04:18:42
(1 day ago)
AutoBlock: ⚙️ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-04 02:20:08
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 20:14:56
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:14:50.217854 2026] [security2:error] [pid 23834:tid 23834] [client 34.47.72.227:34688] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "seymour.freedrm.org"] [uri "/src/.git/config"] [unique_id "apnVOvI1d7AV6ihXwBCxNAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-03 19:53:19
(1 day ago)
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/c ...
show more
"Restricted File Access Attempt - Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"
show less
Web App Attack
Anonymous
2026-09-03 18:19:41
(1 day ago)
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader- ...
show more
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /api/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /site/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /html/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
34.47.72.227 - - [03/Sep/2026:20:19:40 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "cru
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 18:10:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.72.227 (227.72.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:10:38.380184 2026] [security2:error] [pid 12259:tid 12259] [client 34.47.72.227:38312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mainescentsecrets.com"] [uri "/html/.git/config"] [unique_id "apm4Hh7tkZ2CZ0k9BUxflwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-03 08:26:45
(2 days ago)
Multiple WAF Violations
Web App Attack
🇫🇷
Baking333
2026-09-03 08:00:05
(2 days ago)
[redacted] 34.47.72.227 - - [03/Sep/2026:09:00:03 +0100] "GET /api/.git/config HTTP/1.1" 302 6805 0/ ...
show more
[redacted] 34.47.72.227 - - [03/Sep/2026:09:00:03 +0100] "GET /api/.git/config HTTP/1.1" 302 6805 0/168667 "-" "crusader-worker/1.0" [redacted] 34.47.72.227 - - [03/Sep/2026:09:00:03 +0100] "GET /var/www/.git/config HTTP/1.1" 302 6773 0/146176 "-" "crusader-worker/1.0" [redacted] 34.47.72.227 - - [03/Sep/2026:09:00:03 +0100] "GET /public/.git/config HTTP/1.1" 302 6773 0/172488 "-" "crusader-worker/1.0" [redacted] 34.47.72.227 - - [03/Sep/2026:09:00:03 +0100] "GET /www/.git/config HTTP/1.1" 302 6773 0/188557 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 07:45:59
(2 days ago)
Scanner hitting /html/.git/config on natsgw.ara-oman.com (GOOGL-2) — aaguard
Brute-Force
Port Scan