๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 16:07:45
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-02 15:26:58
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.65.195.181 (CH/Switzerland/181.195 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.65.195.181 (CH/Switzerland/181.195.65.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 15:10:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:09:56.046433 2026] [security2:error] [pid 6868:tid 6868] [client 34.65.195.181:53164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.allisonstiles.org"] [uri "/html/.git/config"] [unique_id "apg8RBdJHyYm-7Bz-OfR-gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gamabe
2026-09-02 10:39:05
(7 hours ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
๐ฌ๐ง
pinguin
2026-09-02 10:22:21
(7 hours ago)
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from CH.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /public/.git/config
UA: crusader-worker/1.0
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-02 06:56:44
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:49:56
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:49:49.904215 2026] [security2:error] [pid 11573:tid 11573] [client 34.65.195.181:47342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketfuelpartners.com"] [uri "/api/.git/config"] [unique_id "apfHDbicHXSogpp1z-bEmAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-02 04:44:07
(13 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 04:43:05
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 01:10:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:10:00.747602 2026] [security2:error] [pid 1042456:tid 1042471] [client 34.65.195.181:45430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tahart1.plumeraproductions.com"] [uri "/api/.git/config"] [unique_id "apd3aJHZ0DOpF4nuszEK8wAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 18:28:06
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 18:24:10
(23 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 15:11:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.195.181 (181.195.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:11:12.215597 2026] [security2:error] [pid 22485:tid 22485] [client 34.65.195.181:43746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ursell.org"] [uri "/backend/.git/config"] [unique_id "apbrEOBLqzwOc8e8WqPVxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 14:46:36
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 13:53:45
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking