🇳🇱
e.fierstra
2026-08-29 04:41:58
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 04:01:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:01:35.700797 2026] [security2:error] [pid 31677:tid 31695] [client 34.62.28.133:49220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.supernumerarios.wizart.org"] [uri "/api/.git/config"] [unique_id "apJZn9b8JZEbKsYLT05scwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-08-29 02:25:28
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
factor1
2026-08-29 01:33:04
(1 day ago)
CrowdSec at saturn Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:38:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:38:09.021540 2026] [security2:error] [pid 29808:tid 29911] [client 34.62.28.133:40312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.transiit.org"] [uri "/api/.git/config"] [unique_id "apIb4erV_3_S5WwiJEIqhgAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-28 22:35:04
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 19:03:13
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:03:07.711412 2026] [security2:error] [pid 22664:tid 22664] [client 34.62.28.133:53898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tiki.jeremyscraig.com"] [uri "/app/.git/config"] [unique_id "apHba8xd0fO3CO2EwHkY3AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-08-28 16:21:12
(2 days ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇪🇸
masterguru
2026-08-28 14:02:40
(2 days ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
🇺🇸
TPI-Abuse
2026-08-28 12:48:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:48:39.781899 2026] [security2:error] [pid 3165:tid 3165] [client 34.62.28.133:52508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.edesa.pamplonaserviciotecnico.com"] [uri "/.git/config"] [unique_id "apGDp8Snlm3z7qTjSMvyQQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 12:17:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 08:17:11.310451 2026] [security2:error] [pid 19584:tid 19584] [client 34.62.28.133:33868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smokecooler.com.stlouisdave.com"] [uri "/api/.git/config"] [unique_id "apF8RyfxmkV-6CDi42g62AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-08-28 11:47:08
(2 days ago)
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /www/.git/config HTTP/1.1" 404 4527 "-" "crusader ...
show more
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /www/.git/config HTTP/1.1" 404 4527 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /.git/config HTTP/1.1" 403 468 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /src/.git/config HTTP/1.1" 404 788 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /app/.git/config HTTP/1.1" 404 465 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /backend/.git/config HTTP/1.1" 404 465 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /api/.git/config HTTP/1.1" 404 465 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /www/.git/config HTTP/1.1" 301 566 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /html/.git/config HTTP/1.1" 404 465 "-" "crusader-worker/1.0"
34.62.28.133 - - [28/Aug/2026:13:47:05 +0200] "GET /public/.git/config HTTP/1.1" 404 465 "-" "crusader
show less
Web App Attack
Hacking
🇳🇱
homeshowdomain.nl
2026-08-27 22:01:15
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
🇳🇱
ipoac.nl
2026-08-27 19:48:16
(3 days ago)
ipoac.nl:80 34.62.28.133 - - [27/Aug/2026:21:48:14 +0200] 203.26.133.248 "GET /.git/config HTTP/1.1" ...
show more
ipoac.nl:80 34.62.28.133 - - [27/Aug/2026:21:48:14 +0200] 203.26.133.248 "GET /.git/config HTTP/1.1" 404 1672 "-" "crusader-worker/1.0"
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-27 18:31:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.28.133 (133.28.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:31:00.606057 2026] [security2:error] [pid 3289:tid 3289] [client 34.62.28.133:53810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rockitfish.smogsandiego.com"] [uri "/app/.git/config"] [unique_id "apCCZKpgiUdqko9pK1ks7wAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack