🇬🇧
consul.to
2026-09-06 02:11:47
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
xxkodedxx
2026-09-05 14:20:31
(20 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 23× edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get, 23× edge-block in 10m window.
Origin: JP / AS396982 Google LLC
Active: 14:19:32→14:19:33 UTC
Volume: 23 HTTP req, 1 honeypot probe(s)
Bait taken: /wordpress/.git/config
Status mix: 444×23
Vhost fishing: ip67-217-240-72.pbiaas.com
UA: "crusader-worker/1.0"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇩🇪
spirttm
2026-09-05 09:53:38
(1 day ago)
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /app/.git/config HTTP/1.1" 400 255 "-" "crusader- ...
show more
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /app/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /api/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /public/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /www/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /htdocs/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /site/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /wordpress/.git/config HTTP/1.1" 400 255 "-" "crusader-worker/1.0"
34.84.62.218 - - [05/Sep/2026:09:53:37 +0000] "GET /backend/.git/config HTTP/1.1" 400 255 "-" "
...
show less
Port Scan
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-04 22:58:57
(1 day ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:42
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:33:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:33:45.652705 2026] [security2:error] [pid 3209:tid 3253] [client 34.84.62.218:55876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boxvalleyrockers.com"] [uri "/public/.git/config"] [unique_id "aps5OcLJBHTX2mjZlZLhEwAAAc0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dwmp
2026-09-04 21:24:04
(1 day ago)
[04/Sep/2026:23:24:04.162303 +0200] aps29Ar5kRenbLmcYh6W1QAAAEs 34.84.62.218 59662 38.242.227.117 70 ...
show more
[04/Sep/2026:23:24:04.162303 +0200] aps29Ar5kRenbLmcYh6W1QAAAEs 34.84.62.218 59662 38.242.227.117 7080
[04/Sep/2026:23:24:04.162619 +0200] aps29DX59SPp_kDpbwSGcAAAAAc 34.84.62.218 59648 38.242.227.117 7080
[04/Sep/2026:23:24:04.200880 +0200] aps29K6cLY9V5_KiMYhICAAAAQk 34.84.62.218 59678 38.242.227.117 7080
...
show less
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 20:53:27
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:53:21.821374 2026] [security2:error] [pid 25337:tid 25337] [client 34.84.62.218:42842] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dulcebebe.net"] [uri "/html/.git/config"] [unique_id "apsvwfHwUZDJLx76om1NfgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 19:47:28
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 19:22:51
(1 day ago)
Multiple WAF Violations
Web App Attack
🇮🇹
clamehost.it
2026-09-04 19:02:46
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇩🇪
4server
2026-09-04 19:00:52
(1 day ago)
[FriSep0421:00:49.4643452026][security2:error][pid556385:tid556541][client34.84.62.218:0]ModSecurity ...
show more
[FriSep0421:00:49.4643452026][security2:error][pid556385:tid556541][client34.84.62.218:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"glass-container.com\"][uri\"/wordpress/.git/config\"][unique_id\"apsVYQvTpMytRHRkxPNPgwAAAQU\"]
show less
Port Scan
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 18:53:40
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:47:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:47:09.191657 2026] [security2:error] [pid 19109:tid 19109] [client 34.84.62.218:42110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jerryfeil.com"] [uri "/app/.git/config"] [unique_id "aprn_bZbxONZOEByqnhJnwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:54:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.84.62.218 (218.62.84.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:54:42.995524 2026] [security2:error] [pid 3195504:tid 3195604] [client 34.84.62.218:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "earthtravel.net"] [uri "/app/.git/config"] [unique_id "aprbslcjgI6wol0qY-250gAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack