🇬🇧
Aetherweb Ark
2026-09-06 04:26:13
(56 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.53.211.187 (BE/Belgium/187.211.53.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.53.211.187 (BE/Belgium/187.211.53.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
Gabriel Camargo
2026-09-06 01:27:11
(3 hours ago)
34.53.211.187 - - [05/Sep/2026:20:27:11 -0500] "GET /www/.git/config HTTP/1.1" 301 178 "-" "crusader ...
show more
34.53.211.187 - - [05/Sep/2026:20:27:11 -0500] "GET /www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.53.211.187 - - [05/Sep/2026:20:27:11 -0500] "GET /var/www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.53.211.187 - - [05/Sep/2026:20:27:11 -0500] "GET /public/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
🇳🇱
homeshowdomain.nl
2026-09-05 22:02:47
(7 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:07:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:07:01.254187 2026] [security2:error] [pid 7059:tid 7059] [client 34.53.211.187:53258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barrykrueger.com"] [uri "/html/.git/config"] [unique_id "apyEdbADN6CfKZ_3ftO1fwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-05 14:16:05
(15 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
FD-IX
2026-09-05 08:40:29
(20 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-05 02:36:31
(1 day ago)
233 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇩🇪
Philister11
2026-09-05 01:51:42
(1 day ago)
CrowdSec: crowdsecurity/http-probing (BE/AS396982)
Web App Attack
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:59:15
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:14:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:14:23.685889 2026] [security2:error] [pid 28632:tid 28632] [client 34.53.211.187:56652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.idonthaveawebpage.com"] [uri "/public/.git/config"] [unique_id "aps0r0PSly3X8kPq9hO_7gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
delabiemedia.be
2026-09-04 20:21:49
(1 day ago)
34.53.211.187 - - [04/Sep/2026:22:21:49 +0200] "GET /.git/config HTTP/1.1" 404 162 "-" "crusader-wor ...
show more
34.53.211.187 - - [04/Sep/2026:22:21:49 +0200] "GET /.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.53.211.187 - - [04/Sep/2026:22:21:49 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
NihiliousMonk
2026-09-04 17:25:02
(1 day ago)
Fail2Ban report from jail npm-scanners
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:53:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:53:46.019007 2026] [security2:error] [pid 21891:tid 21891] [client 34.53.211.187:42622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nighthawklabs.com"] [uri "/html/.git/config"] [unique_id "aprpiin-hKsl__B53v6HagAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:44:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.53.211.187 (187.211.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:44:44.004828 2026] [security2:error] [pid 5758:tid 5758] [client 34.53.211.187:55338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benny-wong.net"] [uri "/app/.git/config"] [unique_id "aprLTKELzPgKO0x0VQn_SwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-09-04 09:53:09
(1 day ago)
04/Sep/2026:11:53:09.088255 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
04/Sep/2026:11:53:09.088255 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.53.211.187] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /public/.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "vlc.elhacker.net"] [uri "/public/.git/config"] [unique_id "apqVBV60QODDIXoDrMzh-AAAA8s"]
...
show less
Hacking
Web App Attack