Anonymous
2026-08-28 04:34:58
(4 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
cwytech
2026-08-27 23:43:58
(8 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:50:14
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:50:07.011044 2026] [security2:error] [pid 1771:tid 1771] [client 34.95.238.9:40576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.angove.biz"] [uri "/public/.git/config"] [unique_id "apB4z12S1lWdKz-36uYRXwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:00:44
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:00:35.792290 2026] [security2:error] [pid 18426:tid 18426] [client 34.95.238.9:58062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yohel.org"] [uri "/.git/config"] [unique_id "apAm41K7t94PzFZWfH5rSQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 11:51:20
(20 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-27 11:50:07
(20 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-27 10:45:46
(21 hours ago)
34.95.238.9 - - [27/Aug/2026:06:45:46 -0400] "GET /html/.git/config HTTP/1.0" 403 363 "-" "crusader- ...
show more
34.95.238.9 - - [27/Aug/2026:06:45:46 -0400] "GET /html/.git/config HTTP/1.0" 403 363 "-" "crusader-worker/1.0"
34.95.238.9 - - [27/Aug/2026:06:45:46 -0400] "GET /wordpress/.git/config HTTP/1.0" 403 363 "-" "crusader-worker/1.0"
34.95.238.9 - - [27/Aug/2026:06:45:46 -0400] "GET /site/.git/config HTTP/1.0" 403 363 "-" "crusader-worker/1.0"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 10:04:43
(22 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-08-27 08:51:41
(23 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.95.238.9 (BR/Brazil/9.238.95.34.bc ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.95.238.9 (BR/Brazil/9.238.95.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 05:20:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:19:58.256895 2026] [security2:error] [pid 23293:tid 23321] [client 34.95.238.9:41982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deathbyaudioorg.killerrockandroll.com"] [uri "/api/.git/config"] [unique_id "ao_I_q-g6yR8Vk7dNjFapgAAAZc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 04:30:37
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 03:30:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 23:30:08.696403 2026] [security2:error] [pid 10078:tid 10078] [client 34.95.238.9:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.c2cservices.com"] [uri "/wordpress/.git/config"] [unique_id "ao-vQNiwR92trXvH81eOSgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 02:08:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.238.9 (9.238.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 22:08:45.447617 2026] [security2:error] [pid 10507:tid 10507] [client 34.95.238.9:58756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myduraluxepanel.ipostsocialmedia.com"] [uri "/api/.git/config"] [unique_id "ao-cLS-FOVYe6YgUFqi-2AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-27 00:29:57
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
Philister11
2026-08-27 00:15:17
(1 day ago)
CrowdSec: crowdsecurity/http-probing (BR/AS396982)
Web App Attack
Hacking