๐ฉ๐ช
ghostwarriors
2026-09-24 09:20:08
(58 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-24 09:13:05
(1 hour ago)
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /.git/config HTTP/1.1" 403 4426 "-" "crusader-wor ...
show more
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /.git/config HTTP/1.1" 403 4426 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /backend/.git/config HTTP/1.1" 404 4424 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /public/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /html/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /api/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /app/.git/config HTTP/1.1" 404 4424 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /src/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.66.79.128 - - [24/Sep/2026:11:13:01 +0200] "GET /site/.git/config HTTP/1.1" 404 442
show less
Web App Attack
Hacking
Anonymous
2026-09-24 08:54:10
(1 hour ago)
[24/Sep/2026:08:54:10 +0000] host=demo-amelie.lovelyrender.app server=*.lovelyrender.app ip=34.66.79 ...
show more
[24/Sep/2026:08:54:10 +0000] host=demo-amelie.lovelyrender.app server=*.lovelyrender.app ip=34.66.79.128 method=GET req=/app/.git/config uri=/unknown-host.html status=404 bytes=2592 rt=0.000 urt=- ref="-" ua="crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
4server
2026-09-24 08:45:09
(1 hour ago)
[ThuSep2410:45:07.1368872026][security2:error][pid3430967:tid3431184][client34.66.79.128:0]ModSecuri ...
show more
[ThuSep2410:45:07.1368872026][security2:error][pid3430967:tid3431184][client34.66.79.128:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"dellafoglia.ch.136-243-54-122.cpanel.site\"][uri\"/src/.git/config\"][unique_id\"arTjE1FqE6eYLSzH_e1vhAAAAIE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 08:32:41
(1 hour ago)
[ti-14al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail <name>. Example: 34.66.79.128 - - \[24/Sep/2026:10:32:28 +0200\] "GET /www/.git/config HTTP/1.1" 301 5834 "-" "crusader-worker/1.0"
34.66.79.128 - - \[24/Sep/2026:10:32:28 +0200\] "GET /backend/.git/config HTTP/1.1" 301 5842 "-" "crusader-worker/1.0"
34.66.79.128 - - \[24/Sep/2026:10:32:28 +0200\] "GET /wordpress/.git/config HTTP/1.1" 301 5846 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:32:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:32:06.757583 2026] [security2:error] [pid 17510:tid 17510] [client 34.66.79.128:57590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "decroos.org"] [uri "/app/.git/config"] [unique_id "arTgBrZcC_aS5egeuTlfDQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-24 04:01:20
(6 hours ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:51:34
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:51:29.124843 2026] [security2:error] [pid 19078:tid 19078] [client 34.66.79.128:44942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.progressivefileshare.org"] [uri "/wordpress/.git/config"] [unique_id "arSeQUrhvYTVpzHVqpEXiwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:00:15
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:00:08.200941 2026] [security2:error] [pid 26083:tid 26083] [client 34.66.79.128:38040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.astglobaltech.com"] [uri "/html/.git/config"] [unique_id "arSSOGZB-is8NyOnlbAoKwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:45:02
(8 hours ago)
255 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 21:58:58
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.66.79.128 (128.79.66.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:58:52.382330 2026] [security2:error] [pid 31504:tid 31504] [client 34.66.79.128:44746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cnphilos.com"] [uri "/www/.git/config"] [unique_id "arRLnCWIjrQjdZwUSoP-WwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
jekob
2026-09-23 19:24:17
(14 hours ago)
Automated malicious activity detected (5 events)
Hacking
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-23 18:36:24
(15 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
Anytech
2026-09-23 17:58:00
(16 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-23 14:27:48
(19 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack