๐ฟ๐ฆ
conure.sh
2026-10-07 12:11:17
(1 day ago)
csagent: score 19.9: secrets grab x2; 2 domain(s) in 1s
Web App Attack
๐ง๐ท
radardatelecom
2026-10-06 22:27:03
(1 day ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ซ๐ท
baphomet
2026-10-06 21:52:30
(1 day ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-10-06T21:52:30Z sensor=fail2ban role=web-canary
src=34.86.100.173
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 21:05:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:05:10.921217 2026] [security2:error] [pid 21297:tid 21297] [client 34.86.100.173:59750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.northstar-village.org"] [uri "/.git/config"] [unique_id "asVihszg9sw1fM7e7EoleAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-10-06 21:02:02
(1 day ago)
CMS/framework probe: 34.86.100.173 - - [06/Oct/2026:23:02:01 +0200] "GET /.git/config HTTP/1.1" 404 ...
show more
CMS/framework probe: 34.86.100.173 - - [06/Oct/2026:23:02:01 +0200] "GET /.git/config HTTP/1.1" 404 162 "-" "-" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
๐ฉ๐ช
mravb
2026-10-06 20:52:26
(1 day ago)
34.86.100.173 - - [06/Oct/2026:23:52:24 +0300] "GET /.git/config HTTP/1.1" 444 0 "-" "-"
...
Web App Attack
Hacking
๐ฆ๐บ
2000cn.com.au
2026-10-06 20:48:52
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-06 20:47:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:47:51.721937 2026] [security2:error] [pid 15407:tid 15407] [client 34.86.100.173:32878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.marchand-psych.com"] [uri "/.git/config"] [unique_id "asVed8e4aT3FgpBhyVIhvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 20:14:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.100.173 (173.100.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:14:07.041467 2026] [security2:error] [pid 20525:tid 20525] [client 34.86.100.173:46326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.gmp-ts.com"] [uri "/.git/config"] [unique_id "asVWj74XoNdpv3ddg_4XQgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-10-06 20:02:05
(1 day ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.86.100.173 (US/United States/173.100.8 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 34.86.100.173 (US/United States/173.100.86.34.bc.googleusercontent.com)
show less
Hacking
๐ณ๐ฑ
mieg
2026-10-06 19:56:54
(1 day ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐ต๐ฑ
miriks
2026-10-06 19:35:00
(1 day ago)
Automated scan detected: GET /.git/config
Port Scan
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-06 19:30:20
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ต๐ฑ
Budyn
2026-10-06 19:19:45
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.astropot.online | URI: /.git/config | UA: Unknown User-Agent | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-10-06 19:09:51
(1 day ago)
34.86.100.173 - - [06/Oct/2026:21:09:50 +0200] "GET /.git/config HTTP/1.1" 502 323 "-" "-"
34.86.100 ...
show more
34.86.100.173 - - [06/Oct/2026:21:09:50 +0200] "GET /.git/config HTTP/1.1" 502 323 "-" "-"
34.86.100.173 - - [06/Oct/2026:21:09:50 +0200] "GET /.git/config HTTP/1.1" 502 323 "-" "-"
34.86.100.173 - - [06/Oct/2026:21:09:50 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "-"
...
show less
Web App Attack