๐ฌ๐ง
consul.to
2026-09-24 05:55:39
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:04:26
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:04:22.483430 2026] [security2:error] [pid 18708:tid 18708] [client 34.84.186.81:51698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.biblecalligraphy.com"] [uri "/var/www/.git/config"] [unique_id "arSTNrJjFMlaUXaOImr-mgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:21:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:21:03.292581 2026] [security2:error] [pid 15412:tid 15412] [client 34.84.186.81:36238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.montymilburn.com"] [uri "/src/.git/config"] [unique_id "arSJD8BdEN4f_GBRmJPMEgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bluematrix
2026-09-23 21:26:58
(15 hours ago)
crowdsecurity/http-sensitive-files - Ip 34.84.186.81 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 34.84.186.81 performed 'crowdsecurity/http-sensitive-files' (5 events over 42.748773ms) at 2026-09-23 21:26:58.34620164 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:04:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:04:53.908504 2026] [security2:error] [pid 8339:tid 8339] [client 34.84.186.81:59388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "climasyequipos.com"] [uri "/wordpress/.git/config"] [unique_id "arQ-9ereT2ESlodOKkj0igAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:40:19
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:40:11.289749 2026] [security2:error] [pid 11595:tid 11595] [client 34.84.186.81:37766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "calendar.freedomfactoryteam.com"] [uri "/html/.git/config"] [unique_id "arQA62dbd2I2800awcZzegAAAHo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:08:44
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:08:36.235574 2026] [security2:error] [pid 23979:tid 23979] [client 34.84.186.81:33716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brunerdevelopment.com"] [uri "/src/.git/config"] [unique_id "arPrdJbAR9J7lBxeuEzUiQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 14:07:20
(23 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /www/.git/config (+11 more) | 2026-09-23 14:07 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 14:07:20
(23 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 12:11:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 08:11:14.229137 2026] [security2:error] [pid 4076:tid 4076] [client 34.84.186.81:56122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bidsonlineauctions.com"] [uri "/html/.git/config"] [unique_id "arPB4kMWtQeGBYZxtYRRDgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 10:52:45
(1 day ago)
fail2ban jail apache-secrets-probe: 34.84.186.81 - - [23/Sep/2026:03:52:43 -0700] "GET /htdocs/.git/ ...
show more
fail2ban jail apache-secrets-probe: 34.84.186.81 - - [23/Sep/2026:03:52:43 -0700] "GET /htdocs/.git/config HTTP/1.1" 403 4422 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ฉ๐ช
0x44
2026-09-23 06:47:38
(1 day ago)
TCP SYN Discovery - Flooding
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 06:39:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 02:39:35.485837 2026] [security2:error] [pid 15804:tid 15804] [client 34.84.186.81:39402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.isyourcompanysafe.com"] [uri "/app/.git/config"] [unique_id "arN0JwsPzrmtujwl09hF-gAAAHE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-23 05:42:00
(1 day ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:10:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.186.81 (81.186.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:10:43.905130 2026] [security2:error] [pid 26087:tid 26087] [client 34.84.186.81:59950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.es"] [uri "/site/.git/config"] [unique_id "arNfU-VY0jURbHd3Si9sYQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack