Anonymous
2026-09-03 15:32:35
(2 hours ago)
34.84.12.152 - - [03/Sep/2026:15:32:34 +0000] "GET /app/.git/config HTTP/1.1" 404 162 "-" "crusader- ...
show more
34.84.12.152 - - [03/Sep/2026:15:32:34 +0000] "GET /app/.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
34.84.12.152 - - [03/Sep/2026:15:32:34 +0000] "GET /.git/config HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
kosada.com
2026-09-03 15:09:09
(2 hours ago)
Repeated exploit attempts, for example: /wordpress/.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
π¨π
leo1305
2026-09-03 13:49:13
(4 hours ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 08:04:22
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:04:15.268220 2026] [security2:error] [pid 19005:tid 19005] [client 34.84.12.152:53148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beercruisers.glassicannex.org"] [uri "/src/.git/config"] [unique_id "apkp_yHd5MEiqFOtS9l-1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
arnisolutions
2026-09-03 06:28:41
(11 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-03 and 2026-09-03 (UTC). Sample request: GET /html/.git/config HTTP/1.1
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-03 03:18:50
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 23:18:44.890862 2026] [security2:error] [pid 32335:tid 32335] [client 34.84.12.152:46632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kathiekate.com"] [uri "/public/.git/config"] [unique_id "apjnFGOeV1foHImiRXbmfAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
febrian.de
2026-09-03 01:37:10
(16 hours ago)
Excessive HTTP(S) probing or bad web bot detected by Fail2Ban
Bad Web Bot
Web App Attack
π©πͺ
raph
2026-09-03 00:44:56
(17 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-02 22:01:08
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-02 15:30:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:30:43.180400 2026] [security2:error] [pid 29666:tid 29666] [client 34.84.12.152:49426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lucid-hq.com"] [uri "/api/.git/config"] [unique_id "aphBI4j-4hMMfDOWujlztwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 14:38:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:38:06.609395 2026] [security2:error] [pid 31710:tid 31710] [client 34.84.12.152:50270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kitebeach.deubellzebub.com"] [uri "/src/.git/config"] [unique_id "apg0zmbujZEEMBxPy9HdbwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-09-02 08:02:28
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 06:07:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:07:22.701457 2026] [security2:error] [pid 29235:tid 29235] [client 34.84.12.152:46232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.buildpower.com"] [uri "/.git/config"] [unique_id "ape9GqccGGTSXWLhs0VqoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 05:46:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:46:54.051566 2026] [security2:error] [pid 11725:tid 11758] [client 34.84.12.152:47896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.idwic.com"] [uri "/var/www/.git/config"] [unique_id "ape4Tn4J1nYl8X2EX_PpdwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 05:28:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.12.152 (152.12.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:28:09.626820 2026] [security2:error] [pid 15244:tid 15244] [client 34.84.12.152:36948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.canergy.solar"] [uri "/src/.git/config"] [unique_id "apez6YALsjkF66MGPSrmCAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack