Anonymous
2026-08-29 04:17:29
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:44:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:44:26.423129 2026] [security2:error] [pid 18554:tid 18554] [client 34.97.172.34:41290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4211swf.com.micahgartman.com"] [uri "/public/.git/config"] [unique_id "apI5ehF_iTWVWZL6BEEqHgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-08-28 21:59:11
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
🇳🇿
Antinson
2026-08-28 20:42:24
(2 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-28 16:12:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:12:09.229523 2026] [security2:error] [pid 7948:tid 7948] [client 34.97.172.34:47062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title48.com"] [uri "/backend/.git/config"] [unique_id "apGzWR5ImETV3qhUNpGGbwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-28 14:05:40
(2 days ago)
Multiple WAF Violations
Web App Attack
🇫🇮
paissangroup
2026-08-28 11:56:10
(2 days ago)
Multiple WAF Violations
Web App Attack
🇮🇹
madaello
2026-08-28 11:25:49
(2 days ago)
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /www/.git/config HTTP/1.1" 404 4609 "-" "crusader ...
show more
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /www/.git/config HTTP/1.1" 404 4609 "-" "crusader-worker/1.0"
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /public/.git/config HTTP/1.1" 404 4610 "-" "crusader-worker/1.0"
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /api/.git/config HTTP/1.1" 404 4610 "-" "crusader-worker/1.0"
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /site/.git/config HTTP/1.1" 404 4610 "-" "crusader-worker/1.0"
34.97.172.34 - - [28/Aug/2026:13:25:49 +0200] "GET /html/.git/config HTTP/1.1" 404 4610 "-" "crusader-worker/1.0"
...
show less
Port Scan
Anonymous
2026-08-28 00:06:38
(2 days ago)
Web Server Enforcement Violation.
Hacking
🇺🇸
Axel
2026-08-28 00:05:59
(2 days ago)
Blocked by UFW on LAXHH [443/tcp] | SPT: 58160 | TTL: 55 | LEN: 60 | TOS: 0x00 • Reported by: github ...
show more
Blocked by UFW on LAXHH [443/tcp] | SPT: 58160 | TTL: 55 | LEN: 60 | TOS: 0x00 • Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇧🇾
lns.bz
2026-08-27 23:38:47
(2 days ago)
Too many 404 requests [BY]
Web App Attack
🇳🇱
i-turnradio.nl
2026-08-27 22:59:41
(2 days ago)
2026-08-28 @ 00:59:41 (CET) ~ Blocked for trying to access: /wordpress/.git/config
Web App Attack
🇳🇱
BlueWire Hosting
2026-08-27 22:42:05
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 18:32:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.172.34 (34.172.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:32:45.658246 2026] [security2:error] [pid 27642:tid 27642] [client 34.97.172.34:54654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.raumschach.org.impressionista.net"] [uri "/wordpress/.git/config"] [unique_id "apCCzZO9KRVEueUddl2rXwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-27 12:23:04
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking