๐ฉ๐ช
klaus_ph
2026-09-27 22:16:55
(15 hours ago)
2026-09-26 23:42:50,670 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 34.65.223.145
...
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-26 16:15:23
(1 day ago)
2026-09-25 18:12:15,654 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.65.223.145
.. ...
show more
2026-09-25 18:12:15,654 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.65.223.145
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 08:38:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:38:27.393314 2026] [security2:error] [pid 22771:tid 22771] [client 34.65.223.145:49512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deharrisassoc.com"] [uri "/.git/config"] [unique_id "arThgwWszrdQY8Nf0Ods4gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
i-turnradio.nl
2026-09-24 08:04:58
(4 days ago)
2026-09-24 @ 10:04:50 (CET) ~ Blocked for trying to access: /app/.git/config
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 07:51:55
(4 days ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.65.223.145 - - [24/Sep/2026:09:51:42 +0200] "GET /src/.git/config HTTP/1.1" 403 6415 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:43:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:43:23.487380 2026] [security2:error] [pid 9097:tid 9208] [client 34.65.223.145:53352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dasperformance.com"] [uri "/wordpress/.git/config"] [unique_id "arTUmzDFtWVrZZg3c5AQhAAAAkE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-24 06:55:01
(4 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 04:33:44
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:33:41.187724 2026] [security2:error] [pid 32493:tid 32493] [client 34.65.223.145:37468] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creertest.com.creartest.com"] [uri "/htdocs/.git/config"] [unique_id "arSoJfGhWwO5DoapITqtPQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:31:42
(4 days ago)
583 requests with url.path */.git/config
339 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฎ๐น
VHosting
2026-09-24 01:15:06
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:10:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:10:29.093190 2026] [security2:error] [pid 5343:tid 5343] [client 34.65.223.145:41228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sebog.org"] [uri "/backend/.git/config"] [unique_id "arR4ha3AI05PaTBnjjNlqgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:32:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.223.145 (145.223.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:32:25.492007 2026] [security2:error] [pid 13468:tid 13468] [client 34.65.223.145:50710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "commercialphotostudiorental.com"] [uri "/var/www/.git/config"] [unique_id "arRTearAml6q--te0o0IBwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 22:14:40
(4 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐จ๐ญ
Ribeye375
2026-09-23 21:31:44
(4 days ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack