πΊπΈ
TPI-Abuse
2026-09-02 14:39:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:39:32.973926 2026] [security2:error] [pid 10866:tid 10866] [client 34.62.146.194:45274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jaragoodrich.com"] [uri "/www/.git/config"] [unique_id "apg1JNrrBh3yWzmTIY6uFwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 13:30:31
(6 hours ago)
[ns67.kdns.gr] httpd-config-scan: sites=kapaweb.gr,www.kweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=kapaweb.gr,www.kweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs/access_ssl_log,/var/www/vhosts/system/kapaweb.gr/logs/access_ssl_log,/var/www/vhosts/system/kapaweb.gr/logs/proxy_access_log; samples=/www/.git/config | /app/.git/config | /site/.git/config
show less
Hacking
Web App Attack
π΅π±
sigurg
2026-09-02 13:03:09
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-02 13:00:07
(7 hours ago)
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /var/www/.git/config HTTP/1.1" 404 94432 "-" "cr ...
show more
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /var/www/.git/config HTTP/1.1" 404 94432 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:06 +0200] "GET /var/www/.git/config HTTP/1.1" 404 94177 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /public/.git/config HTTP/1.1" 404 94432 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:06 +0200] "GET /public/.git/config HTTP/1.1" 404 94185 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:06 +0200] "GET /api/.git/config HTTP/1.1" 404 94177 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /api/.git/config HTTP/1.1" 404 94432 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 94432 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:06 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 94177 "-" "crusader-worker/1.0"
34.62.146.194 - - [02/Sep/2026:15:00:05 +0200] "GET /.
...
show less
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-02 07:11:17
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-02 06:02:48
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-02 05:55:31
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:55:22.594797 2026] [security2:error] [pid 30882:tid 30882] [client 34.62.146.194:42524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.travelto.info"] [uri "/htdocs/.git/config"] [unique_id "ape6SkScABAvqs1N9Xbx0gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-02 05:38:33
(14 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
π©πͺ
Starburst SysOp Team
2026-09-02 02:17:45
(18 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-nue6-2)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 00:05:47
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:05:40.928920 2026] [security2:error] [pid 2191:tid 2223] [client 34.62.146.194:52998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.aqutar.com"] [uri "/site/.git/config"] [unique_id "apdoVCmkql07K9FmjBqUhwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-09-02 00:04:54
(20 hours ago)
[WedSep0202:04:50.7882622026][security2:error][pid681765:tid681789][client34.62.146.194:0]ModSecurit ...
show more
[WedSep0202:04:50.7882622026][security2:error][pid681765:tid681789][client34.62.146.194:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gm-swiss.ch.136-243-54-122.cpanel.site\"][uri\"/public/.git/config\"][unique_id\"apdoIvkl0UzTzVbtouU_2QAAAA0\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
SpaceHost-Server
2026-09-01 22:22:17
(22 hours ago)
Brute-Force
Web App Attack
Anonymous
2026-09-01 21:11:34
(23 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π©πͺ
Vegascosmetics
2026-09-01 19:05:44
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 16:30:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.146.194 (194.146.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 12:29:59.573892 2026] [security2:error] [pid 1622:tid 1673] [client 34.62.146.194:39916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "elevapro.com"] [uri "/.git/config"] [unique_id "apb9h-RhgJKWR497SHfEOwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack