|
๐ฌ๐ง
consul.to
|
|
Web attack/malicious scanning detected
|
Web App Attack
|
|
|
๐ณ๐ฑ
WeCloudit-Anti-Abuse
|
|
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
|
Web App Attack
Hacking
|
|
|
๐ต๐พ
armandosaucedo.me
|
|
Threat Intelligence via ARMTI, Web Attack: GET /.git/config
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:44:36.221045 2026] [security2:error] [pid 15197:tid 15197] [client 34.53.166.123:52948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "connectigramme.com.linguistes.com"] [uri "/src/.git/config"] [unique_id "appMtGE_3FyKu0cDCwvoIgAAAAE"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฌ๐ง
foxxelabs
|
|
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Kn ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /.git/config | Project: anseo | Reason(s): Known exploit path: /.git/config | User-Agent: crusader-worker/1.0
show less
|
Web App Attack
|
|
|
๐ฉ๐ช
HERA - Operations
|
|
sensobox - searching for vulnerable scripts: config 2026/09/03 22:00:56
|
Web App Attack
|
|
|
๐ฒ๐พ
Rizzy
|
|
Multiple WAF Violations
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
dynamix
|
|
Multiple WAF Violations
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:40:46.413554 2026] [security2:error] [pid 6722:tid 6722] [client 34.53.166.123:44628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ohnosound.com"] [uri "/wordpress/.git/config"] [unique_id "apmjDmWdc482uyt5emSheQAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:01:08.227979 2026] [security2:error] [pid 20405:tid 20405] [client 34.53.166.123:46582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zenventures.co.uk"] [uri "/site/.git/config"] [unique_id "apmZxKtThrqRnPrXXRWPFgAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
ghostwarriors
|
|
Attempts against non-existent wp-login
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
yitzhaq
|
|
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /.git/config HTTP/1.1" 403 457 "-" "crusader-wor ...
show more
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /.git/config HTTP/1.1" 403 457 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /www/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /html/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /site/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /src/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /var/www/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 454 "-" "crusader-worker/1.0"
34.53.166.123 - - [03/Sep/2026:16:48:55 +0200] "GET /api/.git/config HTTP/1.1" 404 45
show less
|
Web App Attack
Hacking
|
|
|
๐ฉ๐ช
SwinT
|
|
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
|
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.166.123 (123.166.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:22:52.116068 2026] [security2:error] [pid 25496:tid 25496] [client 34.53.166.123:57468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.basselier.com"] [uri "/wordpress/.git/config"] [unique_id "aplmnJx3nm3tOuhl9p9cUAAAAAM"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ซ๐ฎ
paissangroup
|
|
Multiple WAF Violations
|
Web App Attack
|
|