ππΊ
DumaNet
2026-08-27 12:35:00
(24 minutes ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 07:03:48
Source IP: 34.64. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 27. 07:03:48
Source IP: 34.64.152.227
Portion of the log(s):
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /api/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /src/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /public/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /site/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /app/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /backend/.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /.git/config HTTP/1.1" 404 153 "-" "crusader-worker/1.0"
34.64.152.227 - [27/Aug/2026:07:03:48 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 153 "-" "crusade
show less
Web App Attack
πΊπΈ
wteiken
2026-08-27 11:27:09
(1 hour ago)
2026-08-27T07:27:06.748696-04:00 nostromo.teiken.net kernel: [294643.363583] syn_limit:IN=en-wan OUT ...
show more
2026-08-27T07:27:06.748696-04:00 nostromo.teiken.net kernel: [294643.363583] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.64.152.227 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=34795 DF PROTO=TCP SPT=42248 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-27T07:27:06.749063-04:00 nostromo.teiken.net kernel: [294643.363663] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.64.152.227 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=26153 DF PROTO=TCP SPT=42236 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-27T07:27:07.779426-04:00 nostromo.teiken.net kernel: [294644.394302] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=34.64.152.227 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x60 TTL=61 ID=34796 DF PROTO=TCP SPT=42248 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-08-27T07:27:07.779684-04:00 nostromo.teiken.net kernel: [294644.394384] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:
...
show less
Port Scan
π³π±
e.fierstra
2026-08-27 05:14:52
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
inlink.ltd
2026-08-27 04:25:14
(8 hours ago)
dot file probe
Web App Attack
π©πͺ
4server
2026-08-27 04:19:29
(8 hours ago)
[ThuAug2706:19:23.7328052026][security2:error][pid648213:tid648310][client34.64.152.227:0]ModSecurit ...
show more
[ThuAug2706:19:23.7328052026][security2:error][pid648213:tid648310][client34.64.152.227:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.nuovodominio.sito-online.ch\"][uri\"/src/.git/config\"][unique_id\"ao-6y8t49gajakldW0eayQAAAQA\"]
show less
Port Scan
Brute-Force
Web App Attack
π«π·
masterguru
2026-08-06 04:17:04
(3 weeks ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
π¬π§
consul.to
2026-08-06 01:53:40
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
dbmwebdesign
2026-08-05 17:50:23
(3 weeks ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-08-05 17:15:47
(3 weeks ago)
[Wed Aug 05 19:15:46.407954 2026] [:error] [pid 1680169:tid 1680169] [client 34.64.152.227:41134] Mo ...
show more
[Wed Aug 05 19:15:46.407954 2026] [:error] [pid 1680169:tid 1680169] [client 34.64.152.227:41134] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/html/.git/config' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .git/ found within REQUEST_FILENAME: /html/.git/config"] [severity "2"] [ver "OWASP_CRS/4.29.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/html/.git/config"] [unique_id "178595014662.785317"] [ref "o6,5v4,17t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Wed Aug 05 19:15:46.419397 2026] [:error] [pid 1733170:tid 1733170] [client 34.64.152
...
show less
Web App Attack
π΅π±
Budyn
2026-08-05 14:12:44
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: tug.budyn.wtf | URI: /.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-05 13:16:28
(3 weeks ago)
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: crusader-w ...
show more
CrowdSec: crowdsecurity/http-sensitive-files | req: /.git/config | 5 distinct paths | UA: crusader-worker/1.0
show less
Hacking
π©πͺ
FeG Deutschland
2026-08-05 09:16:28
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
NXTwoThou
2026-08-05 07:37:50
(3 weeks ago)
/public/.git/config
Web App Attack
π©πͺ
big-cloud.nl
2026-08-05 03:05:46
(3 weeks ago)
Try to access /htdocs/.git/config
Web App Attack
π©πͺ
KiekerJan
2026-08-04 19:02:05
(3 weeks ago)
34.64.152.227 - - [04/Aug/2026:21:02:05 +0200] "GET /html/.git/config HTTP/1.1" 301 162 "-" "crusade ...
show more
34.64.152.227 - - [04/Aug/2026:21:02:05 +0200] "GET /html/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
34.64.152.227 - - [04/Aug/2026:21:02:05 +0200] "GET /htdocs/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack