๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-17 03:24:22
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 02:53:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:53:49.639094 2026] [security2:error] [pid 9001:tid 9001] [client 34.65.191.173:46690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stpetersplayers.co.uk"] [uri "/.git/config"] [unique_id "aqtWPcMeTeAHbghuAnhwEgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:15:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:15:00.460498 2026] [security2:error] [pid 16533:tid 16533] [client 34.65.191.173:54312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sanesoftware.com"] [uri "/.git/config"] [unique_id "aqrcpGZlJsZQg1Bz3SygTgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 18:15:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 17:45:05
(3 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:04:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:04:07.823225 2026] [security2:error] [pid 28759:tid 28759] [client 34.65.191.173:42324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandpointidaho.com"] [uri "/.git/config"] [unique_id "aqrMB5s2RaJducHC09FdbgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:43:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:43:43.980881 2026] [security2:error] [pid 26310:tid 26320] [client 34.65.191.173:37238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandiegosamband.com"] [uri "/.git/config"] [unique_id "aqrHP9Dlb-hU_0ka3N3jwwAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:27:55
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:27:51.864311 2026] [security2:error] [pid 10791:tid 10791] [client 34.65.191.173:43054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandhage.com"] [uri "/.git/config"] [unique_id "aqrDh1oZ91ot9kyt8rBFXAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-16 16:19:13
(3 days ago)
Try to access /.git/config
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 16:17:13
(3 days ago)
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34 ...
show more
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.65.191.173 - - \[16/Sep/2026:18:17:04 +0200\] "GET /.git/config HTTP/1.1" 307 345 "-" "Mozilla/5.0 \(Windows NT 10.0\; Win64\; x64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 16:08:52
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:07:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.191.173 (173.191.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:07:07.852244 2026] [security2:error] [pid 23101:tid 23101] [client 34.65.191.173:39526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandboxspeech.org.abbysue.com"] [uri "/.git/config"] [unique_id "aqq-q1mLcS9j1Fq_da7bJQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 15:31:02
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+17 more) | 2026-09-16 15:31 UTC
show less
Hacking
Web App Attack
๐ฏ๐ต
beon
2026-09-16 14:46:08
(3 days ago)
[DateTime=>2026-09-16T14:46:08Z to 2026-09-16T14:47:58Z (UTC)] , [HoneyPot_Hits=>226 times] , [Honey ...
show more
[DateTime=>2026-09-16T14:46:08Z to 2026-09-16T14:47:58Z (UTC)] , [HoneyPot_Hits=>226 times] , [HoneyPots=>/.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development and others] , [404targets=>/phpinfo, /dev/phpinfo.php, /old/phpinfo.php, /public/phpinfo.php, /info, /server-status.php and others] , [total_Hits=>271 times] , [Keyword=>WordPress, Joomla, Laravel]
show less
Bad Web Bot
Web App Attack
Hacking