Anonymous
2026-09-25 02:00:31
(36 minutes ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-24 12:01:44
(14 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-24 08:39:35
(17 hours ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:47:44
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:47:38.222475 2026] [security2:error] [pid 17768:tid 17768] [client 34.65.124.164:35718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ozarktulsa.com"] [uri "/html/.git/config"] [unique_id "arSdWvmU63T2gidzVG-V8wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:56:03
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:55:59.675049 2026] [security2:error] [pid 28177:tid 28177] [client 34.65.124.164:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.365soft.top"] [uri "/backend/.git/config"] [unique_id "arSRPzIRomT0AEMiB2tDfQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:09:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:09:27.290587 2026] [security2:error] [pid 2835:tid 2835] [client 34.65.124.164:51732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.isyourcompanysafe.com"] [uri "/api/.git/config"] [unique_id "arSGV6_6qPZspa-OeBCxogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:40:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:40:02.073661 2026] [security2:error] [pid 13899:tid 13899] [client 34.65.124.164:42748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.asiancommoditiescorporation.com"] [uri "/var/www/.git/config"] [unique_id "arR_cjHxLySfjoVUtZjoBQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 23:27:23
(1 day ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ช๐ธ
robotstxt
2026-09-23 23:19:27
(1 day ago)
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /.git/config HTTP/1.1" 403 189 "-" "crusader-wor ...
show more
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-"
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /site/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-"
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /src/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-"
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /var/www/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-"
34.65.124.164 - - [23/Sep/2026:23:18:25 +0000] "GET /api/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-"
...
show less
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-23 23:00:06
(1 day ago)
Automated ban via infra-monitor: mgmt-path-probe, suspicious-probe
Port Scan
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 22:54:06
(1 day ago)
[24/Sep/2026:01:54:06 +0300] -- 34.65.124.164 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[24/Sep/2026:01:54:06 +0300] -- 34.65.124.164 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:04:13
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 21:36:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.124.164 (164.124.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:36:15.732752 2026] [security2:error] [pid 8850:tid 8850] [client 34.65.124.164:35830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clubfansite.com"] [uri "/www/.git/config"] [unique_id "arRGT89hSxYvOh4--_HszAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-23 18:40:17
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 18:36:35
(1 day ago)
$f2bV_matches
Brute-Force