🇳🇴
jad-abuse
2026-08-29 09:49:28
(23 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 36 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 02:20:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:20:05.345307 2026] [security2:error] [pid 21432:tid 21432] [client 34.91.178.67:53794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ecoventionsusa.com.salsberggroup.com"] [uri "/api/.git/config"] [unique_id "apJB1avQtVRuOhyjOS2AQgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-29 01:18:32
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:17:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:17:30.296076 2026] [security2:error] [pid 4730:tid 4730] [client 34.91.178.67:46310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "illinois-online.org"] [uri "/site/.git/config"] [unique_id "apIzKvnHInypunFcs8z6-wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:32:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:32:16.913858 2026] [security2:error] [pid 16454:tid 16454] [client 34.91.178.67:49504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnic.games.websiterescuecontest.com"] [uri "/var/www/.git/config"] [unique_id "apIagIZjrUj3NkT1A6tqkAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-08-28 22:36:27
(1 day ago)
80,443
Brute-Force
SSH
🇩🇪
4server
2026-08-28 21:59:37
(1 day ago)
[FriAug2823:59:32.8598512026][security2:error][pid3218890:tid3218955][client34.91.178.67:0]ModSecuri ...
show more
[FriAug2823:59:32.8598512026][security2:error][pid3218890:tid3218955][client34.91.178.67:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.alfagamma.ch.136-243-54-122.cpanel.site\"][uri\"/api/.git/config\"][unique_id\"apIExDTS87Tw1q0K352jSgAAAA8\"]
show less
Port Scan
Brute-Force
Web App Attack
🇩🇪
lolyay
2026-08-28 21:03:22
(1 day ago)
34.91.178.67 - - [28/Aug/2026:21:03:21 +0000] "GET /www/.git/config HTTP/1.1" 200 4 "-" "crusader-wo ...
show more
34.91.178.67 - - [28/Aug/2026:21:03:21 +0000] "GET /www/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
34.91.178.67 - - [28/Aug/2026:21:03:21 +0000] "GET /wordpress/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-28 18:41:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:41:44.454418 2026] [security2:error] [pid 3199:tid 3199] [client 34.91.178.67:35368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.turtle-traps.com.cajunfriedturkey.com"] [uri "/wordpress/.git/config"] [unique_id "apHWaBUVwJHhP36JViz7nAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-28 17:31:27
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-28 15:14:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 11:14:39.887079 2026] [security2:error] [pid 2896:tid 2896] [client 34.91.178.67:51926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.joesteiner.com"] [uri "/www/.git/config"] [unique_id "apGl34J_Q0ZIWQ0HEMduSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 13:35:02
(1 day ago)
suspicious request in access.log
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 11:15:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:15:42.146455 2026] [security2:error] [pid 24013:tid 24013] [client 34.91.178.67:38776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dryrot.corepest.com"] [uri "/htdocs/.git/config"] [unique_id "apFt3h3tTm-jJIJiOgNchAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-08-27 22:02:42
(2 days ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:09:04
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.178.67 (67.178.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:08:57.697367 2026] [security2:error] [pid 28966:tid 28966] [client 34.91.178.67:60862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alexlacruz.com"] [uri "/.git/config"] [unique_id "apB9OXC1km4Hfuc4NJMpVQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack