๐บ๐ธ
antlac1
2026-08-28 23:20:18
(1 month ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
pigro
2026-08-28 22:58:01
(1 month ago)
34.81.135.16 - - [29/Aug/2026:00:58:00 +0200] "GET /api/.git/config HTTP/1.1" 301 5 "-" "crusader-wo ...
show more
34.81.135.16 - - [29/Aug/2026:00:58:00 +0200] "GET /api/.git/config HTTP/1.1" 301 5 "-" "crusader-worker/1.0"
34.81.135.16 - - [29/Aug/2026:00:58:00 +0200] "GET /api/.git/config HTTP/1.1" 301 69 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ฎ๐น
clamehost.it
2026-08-28 21:23:43
(1 month ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ธ๐ช
vaia.cloud
2026-08-28 20:35:03
(1 month ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-08-28 11:28:23
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-08-28 11:21:00
(1 month ago)
34.81.135.16 - - [28/Aug/2026:13:20:51 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 146 "-" "crusad ...
show more
34.81.135.16 - - [28/Aug/2026:13:20:51 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.81.135.16 - - [28/Aug/2026:13:20:51 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
34.81.135.16 - - [28/Aug/2026:13:20:51 +0200] "GET /app/.git/config HTTP/1.1" 403 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:52:21
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:52:14.695006 2026] [security2:error] [pid 27016:tid 27016] [client 34.81.135.16:33998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.koreagreenrecycling.com"] [uri "/var/www/.git/config"] [unique_id "apFoXiDx68A0D7VvupMI7gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 04:35:12
(1 month ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-27 18:21:00
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:20:53.829683 2026] [security2:error] [pid 522:tid 522] [client 34.81.135.16:51688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customwww.com"] [uri "/api/.git/config"] [unique_id "apCABYoVS0fiOTWgeE9ITQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-27 14:56:09
(1 month ago)
-.nl:443 34.81.135.16 - - [27/Aug/2026:16:56:08 +0200] -.nl "GET /var/www/.git/config HTTP/1.1" 404 ...
show more
-.nl:443 34.81.135.16 - - [27/Aug/2026:16:56:08 +0200] -.nl "GET /var/www/.git/config HTTP/1.1" 404 6427 "-" "crusader-worker/1.0"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-27 09:40:53
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:40:44.474222 2026] [security2:error] [pid 26053:tid 26053] [client 34.81.135.16:59632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepert.com"] [uri "/htdocs/.git/config"] [unique_id "apAGHJXCuUDV1HpbT1luDQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 07:08:31
(1 month ago)
[Thu Aug 27 09:08:30.625463 2026] [:error] [pid 1555078:tid 1555078] [client 34.81.135.16:43680] Mod ...
show more
[Thu Aug 27 09:08:30.625463 2026] [:error] [pid 1555078:tid 1555078] [client 34.81.135.16:43680] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/app/.git/config' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .git/ found within REQUEST_FILENAME: /app/.git/config"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/app/.git/config"] [unique_id "178781451086.396457"] [ref "o5,5v4,16t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Thu Aug 27 09:08:30.629139 2026] [:error] [pid 1555076:tid 1555076] [client 34.81.135.16
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 05:50:06
(1 month ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ญ๐ณ
soporte
2026-08-27 05:16:42
(1 month ago)
Probe for vulnerabilities. Path attempted: /api/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 04:59:02
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.81.135.16 (16.135.81.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 00:58:53.258915 2026] [security2:error] [pid 13426:tid 13426] [client 34.81.135.16:56738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lewiscountyfair.ewingmissouri.com"] [uri "/var/www/.git/config"] [unique_id "ao_EDUL79fDzto0iAdEdEwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack