๐ฉ๐ช
FD-IX
2026-09-24 08:36:21
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 07:11:26
(11 hours ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.65.101.218 - - [24/Sep/2026:09:11:25 +0200] "GET /var/www/.git/config HTTP/1.1" 403 6297 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:04:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:04:40.859959 2026] [security2:error] [pid 3640219:tid 3640219] [client 34.65.101.218:34792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dance4ovations.com"] [uri "/.git/config"] [unique_id "arTLiI4DqNxVRSBAN2IorwAAAHo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-24 07:04:38
(11 hours ago)
[Thu Sep 24 17:04:38.292567 2026] [security2:error] [pid 483748] [client 34.65.101.218:56054] [clien ...
show more
[Thu Sep 24 17:04:38.292567 2026] [security2:error] [pid 483748] [client 34.65.101.218:56054] [client 34.65.101.218] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "arTLhvmi_vvPj62gHdVy4gAAABI"]
...
show less
Web App Attack
๐จ๐ฟ
ddw
2026-09-24 05:41:48
(13 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:06:24
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:06:18.421069 2026] [security2:error] [pid 26753:tid 26753] [client 34.65.101.218:37370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.hvacs-aircon.com"] [uri "/public/.git/config"] [unique_id "arSFmtPkov1wp0GAxi-PCQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:36:36
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:36:29.818885 2026] [security2:error] [pid 9206:tid 9206] [client 34.65.101.218:58464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.179vfs.com"] [uri "/.git/config"] [unique_id "arR-nbizFNiqA0UqsMnahwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:23:19
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:23:12.583356 2026] [security2:error] [pid 11272:tid 11272] [client 34.65.101.218:45574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.erkan.net"] [uri "/public/.git/config"] [unique_id "arRtcK2jKt3DF8xIOm3aegAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:07:30
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:07:26.168087 2026] [security2:error] [pid 5976:tid 5976] [client 34.65.101.218:42148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackballprojects.com"] [uri "/www/.git/config"] [unique_id "arRpvu1fQPbsp9TzK82MQwAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 19:25:36
(23 hours ago)
34.65.101.218 - - [23/Sep/2026:16:25:36 -0300] "GET /.git/config HTTP/1.1" 403 1810 "-" "crusader-wo ...
show more
34.65.101.218 - - [23/Sep/2026:16:25:36 -0300] "GET /.git/config HTTP/1.1" 403 1810 "-" "crusader-worker/1.0"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
Anonymous
2026-09-23 17:55:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 17:45:26
(1 day ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /public/.git/config (+11 more) | 2026-09-23 17:45 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:42:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:42:39.541026 2026] [security2:error] [pid 26090:tid 26095] [client 34.65.101.218:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "callaplusfirst.com"] [uri "/var/www/.git/config"] [unique_id "arQBf9udbNmWONxxxcSm_QAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 12:28:26
(1 day ago)
[23/Sep/2026:15:28:26 +0300] -- 34.65.101.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[23/Sep/2026:15:28:26 +0300] -- 34.65.101.218 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:04:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.101.218 (218.101.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:04:55.474169 2026] [security2:error] [pid 21369:tid 21369] [client 34.65.101.218:50376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bhartman.com"] [uri "/backend/.git/config"] [unique_id "arPAZ9Ru28p0HCA2IrGtTgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack