🇫🇷
masterguru
2026-09-04 00:05:40
(3 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.50.100.127 (ID/Indonesia/127.100.5 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.50.100.127 (ID/Indonesia/127.100.50.34.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇨🇭
copestack
2026-09-03 22:00:08
(5 hours ago)
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ...
show more
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ov-4e5936.
show less
Web App Attack
Anonymous
2026-09-03 20:13:40
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-03 19:43:54
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-03 19:08:18
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.50.100.127 (ID/Indonesia/127.100.50.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.50.100.127 (ID/Indonesia/127.100.50.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-03 18:40:48
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:51:23
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:51:14.711237 2026] [security2:error] [pid 31386:tid 31386] [client 34.50.100.127:56290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saladmasterhealth.starrmail.net"] [uri "/src/.git/config"] [unique_id "apmlggE43wnxP8-M0AFj-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:18:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:18:15.589089 2026] [security2:error] [pid 32576:tid 32576] [client 34.50.100.127:38660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gescosigns.com"] [uri "/src/.git/config"] [unique_id "apmdx2yanQoEg4twUcL9sAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 15:12:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:12:47.006725 2026] [security2:error] [pid 9131:tid 9131] [client 34.50.100.127:36674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "millergrain.com"] [uri "/backend/.git/config"] [unique_id "apmOb_bBowZrOLfBgX0diAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 14:39:30
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:39:24.751556 2026] [security2:error] [pid 22901:tid 22901] [client 34.50.100.127:38280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fourmarket.com.joqlawncare.com"] [uri "/.git/config"] [unique_id "apmGnHyrQQevH2_9CjatPAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-03 08:51:33
(18 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 07:30:03
(19 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
Copious7283
2026-09-03 06:45:42
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 06:32:44
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.100.127 (127.100.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:32:36.006752 2026] [security2:error] [pid 17274:tid 17274] [client 34.50.100.127:59764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexissteinrauf.com"] [uri "/site/.git/config"] [unique_id "apkUhHhHrLwdO4yZ_o66IwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 04:54:53
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking