๐บ๐ธ
TPI-Abuse
2026-09-24 07:06:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:06:33.069394 2026] [security2:error] [pid 17447:tid 17447] [client 34.65.144.214:34566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "danielbrower.com"] [uri "/html/.git/config"] [unique_id "arTL-RptMfLbWN4DrIfUKQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-24 07:05:43
(2 days ago)
[24/Sep/2026:10:05:43 +0300] -- 34.65.144.214 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[24/Sep/2026:10:05:43 +0300] -- 34.65.144.214 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 05:01:11
(3 days ago)
[cb-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-11al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.65.144.214 - - [24/Sep/2026:07:00:50 +0200] "GET /var/www/.git/config HTTP/1.1" 403 6205 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:25:41
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:25:38.355654 2026] [security2:error] [pid 8813:tid 8813] [client 34.65.144.214:34912] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/api/.git/config"] [unique_id "arSmQuUhnYa84vsPTEQrCAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-24 00:46:13
(3 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 17 unauthorized requests recorded between 2026-09-23 00:42:49 UTC and 2026-09-23 00:42:51 UTC (rate: ~17 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-23 00:42:51 UTC] IP: 34.65.144.214 - W3C IIS (Port 80): GET /src/.git/config -> HTTP 500 [CLIENT: 34.65.144.214]
[2026-09-23 00:42:51 UTC] IP: 34.65.144.214 - W3C IIS (Port 80): GET /api/.git/config -> HTTP 500 [CLIENT: 34.65.144.214]
[2026-09-23 00:42:51 UTC] IP: 34.65.144.214 - W3C IIS (Port 80): GET /public/.git/config -> HTTP 500 [CLIENT: 34.65.144.214]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:47:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:47:33.878035 2026] [security2:error] [pid 23641:tid 23641] [client 34.65.144.214:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "concealed.cloudex.click"] [uri "/backend/.git/config"] [unique_id "arRXBZZVikvNaL4s6H4qpQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:04:14
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 20:21:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:21:27.215770 2026] [security2:error] [pid 22482:tid 22482] [client 34.65.144.214:38784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citizens-referendum.eu"] [uri "/api/.git/config"] [unique_id "arQ0x1Cz1F6KJ0Wojhs38gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:56:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:56:09.525003 2026] [security2:error] [pid 18353:tid 18353] [client 34.65.144.214:39780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "christianbroadcastingleague.com"] [uri "/www/.git/config"] [unique_id "arQu2XgAjdalPhFCqmi7EQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:08:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:08:38.976776 2026] [security2:error] [pid 15416:tid 15416] [client 34.65.144.214:33498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ccoxes.com"] [uri "/var/www/.git/config"] [unique_id "arQVplljgL89ZGUATfdkMwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 14:49:22
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฆ๐บ
secnicholas
2026-09-23 13:27:50
(3 days ago)
Banned by CrowdSec - scenario: crowdsecurity/http-sensitive-files
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:00:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.144.214 (214.144.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:00:50.965285 2026] [security2:error] [pid 24427:tid 24427] [client 34.65.144.214:56268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blastjet.net"] [uri "/www/.git/config"] [unique_id "arPNgqjMyr4bszUY0D1s8wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:52
(3 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 10:54:29
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack