π¦πΊ
A.i.D.A.N.N
2026-09-02 08:08:09
(6 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 08:05:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:05:06.244744 2026] [security2:error] [pid 22711:tid 22711] [client 34.57.226.163:56816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosacid.com"] [uri "/site/.git/config"] [unique_id "apfYslESS_FunBe_JGmKqgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 07:10:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:10:02.972595 2026] [security2:error] [pid 18717:tid 18717] [client 34.57.226.163:60560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rossiolympusjr.themotelwest.com"] [uri "/html/.git/config"] [unique_id "apfLyvPf1e0JcYN60GxHqgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yvoictra
2026-09-02 03:47:57
(10 hours ago)
Bloqueado automΓ‘ticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
π©πͺ
Marc
2026-09-02 00:24:54
(14 hours ago)
34.57.226.163 - - [02/Sep/2026:02:24:54 +0200] "GET /backend/.git/config HTTP/1.1" 404 4618 "-" "cru ...
show more
34.57.226.163 - - [02/Sep/2026:02:24:54 +0200] "GET /backend/.git/config HTTP/1.1" 404 4618 "-" "crusader-worker/1.0" 34.57.226.163 - - [02/Sep/2026:02:24:54 +0200] "GET /.git/config HTTP/1.1" 404 4616 "-" "crusader-worker/1.0" 34.57.226.163 - - [02/Sep/2026:02:24:54 +0200] "GET /src/.git/config HTTP/1.1" 404 4618 "-" "crusader-worker/1.0"
show less
Brute-Force
π§π·
dominioz
2026-09-02 00:24:42
(14 hours ago)
2026-09-02 00:24:33 GET /www/.git/config - - 34.57.226.163 HTTP/1.1 crusader-worker/1.0 - 301 590
20 ...
show more
2026-09-02 00:24:33 GET /www/.git/config - - 34.57.226.163 HTTP/1.1 crusader-worker/1.0 - 301 590
2026-09-02 00:24:33 GET /public/.git/config - - 34.57.226.163 HTTP/1.1 crusader-worker/1.0 - 301 596
2026-09-02 00:24:33 GET /.git/config - - 34.57.226.163 HTTP/1.1 crusader-worker/1.0 - 301 582
2026-09-02 00:24:33 GET /html/.git/config - - 34.57.226.163 HTTP/1.1 crusader-worker/1.0 - 301 592
...
show less
Web App Attack
π«π·
masterguru
2026-09-02 00:24:20
(14 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.57.226.163 (US/United States/163.2 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.57.226.163 (US/United States/163.226.57.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
Anonymous
2026-09-02 00:13:04
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π©πͺ
MSC IT for Business GmbH
2026-09-02 00:05:04
(14 hours ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 23:59:18
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:59:10.624537 2026] [security2:error] [pid 27144:tid 27144] [client 34.57.226.163:59260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.studioarts.net"] [uri "/var/www/.git/config"] [unique_id "apdmzjrSkYfp00jAKBfY1gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-01 23:14:23
(15 hours ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
Epimetheus
2026-09-01 22:54:04
(15 hours ago)
Unauthorized access attempts:
[GET] /app/.git/config
[GET] /api/.git/config
[GET] /public/.git/conf ...
show more
Unauthorized access attempts:
[GET] /app/.git/config
[GET] /api/.git/config
[GET] /public/.git/config
[GET] /backend/.git/config
[GET] /.git/config
[GET] /wordpress/.git/config
[GET] /public/.git/config
[GET] /src/.git/config
[GET] /htdocs/.git/config
[GET] /src/.git/config
[GET] /backend/.git/config
[GET] /www/.git/config
[GET] /wordpress/.git/config
[GET] /htdocs/.git/config
[GET] /api/.git/config
[GET] /site/.git/config
[GET] /site/.git/config
UA: crusader-worker/1.0
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-01 22:33:41
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 18:18:01
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.226.163 (163.226.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:17:54.685100 2026] [security2:error] [pid 8189:tid 8189] [client 34.57.226.163:52234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.crucialpins.com"] [uri "/api/.git/config"] [unique_id "apcW0gifCkY23MIdiykYuAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-09-01 18:16:14
(20 hours ago)
[TueSep0120:16:09.0923512026][security2:error][pid181816:tid181913][client34.57.226.163:0]ModSecurit ...
show more
[TueSep0120:16:09.0923512026][security2:error][pid181816:tid181913][client34.57.226.163:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"cpanel.carolin-mizio.ch\"][uri\"/htdocs/.git/config\"][unique_id\"apcWaUOuZZavar5BxDJpBAAAAAk\"]
show less
Hacking
Web App Attack