๐ฉ๐ช
ghostwarriors
2026-09-02 08:20:06
(3 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 08:01:27
(3 hours ago)
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /.git/config HTTP/1.1" 403 4423 "-" "crusader-wor ...
show more
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /.git/config HTTP/1.1" 403 4423 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /src/.git/config HTTP/1.1" 404 46318 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /site/.git/config HTTP/1.1" 404 46318 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /www/.git/config HTTP/1.1" 404 46316 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /.git/config HTTP/1.1" 301 519 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 46316 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /backend/.git/config HTTP/1.1" 404 46318 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /var/www/.git/config HTTP/1.1" 404 46316 "-" "crusader-worker/1.0"
34.97.247.83 - - [02/Sep/2026:10:01:21 +0200] "GET /api/.git/config HTTP/1.1" 404 46317
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 07:24:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:23:58.763457 2026] [security2:error] [pid 9285:tid 9285] [client 34.97.247.83:36714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-slovenia.com"] [uri "/var/www/.git/config"] [unique_id "apfPDjMM3rITO-cuCnTkwQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:47:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:47:39.233113 2026] [security2:error] [pid 4625:tid 4625] [client 34.97.247.83:43524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dryprodrain.com"] [uri "/www/.git/config"] [unique_id "ape4e0mg2CLxmFA5yW2Q5AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:51:39
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:51:32.628408 2026] [security2:error] [pid 24375:tid 24375] [client 34.97.247.83:40640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.sokolskiy.com"] [uri "/src/.git/config"] [unique_id "apdzFF5OMjxeipCfeAoqhQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-02 00:45:12
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-02 00:36:02
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:13:00
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:12:55.485374 2026] [security2:error] [pid 29425:tid 29425] [client 34.97.247.83:48032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toody.com"] [uri "/.git/config"] [unique_id "apdb96TknkNpHNyWEXnSvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:15:18
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:15:03.847005 2026] [security2:error] [pid 8878:tid 8878] [client 34.97.247.83:56642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "breathofgodministry.mroxygen.org"] [uri "/app/.git/config"] [unique_id "apdOZ0O00h6Kui7UkuzmcgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-09-01 21:10:16
(14 hours ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 21:09:19
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:09:15.366899 2026] [security2:error] [pid 24699:tid 24699] [client 34.97.247.83:42178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "notify.ev.alitcogroup.com"] [uri "/.git/config"] [unique_id "apc--3K4nvQzo_Z3VlbqzgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 21:03:24
(14 hours ago)
34.97.247.83 - - [01/Sep/2026:23:03:19 +0200] "GET /site/.git/config HTTP/1.1" 404 146 "-" "crusader ...
show more
34.97.247.83 - - [01/Sep/2026:23:03:19 +0200] "GET /site/.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Anonymous
2026-09-01 20:59:33
(14 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 18:22:20
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.247.83 (83.247.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:22:12.226018 2026] [security2:error] [pid 22220:tid 22220] [client 34.97.247.83:38992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.muslera.com"] [uri "/site/.git/config"] [unique_id "apcX1IaGYiATomLfeZVc7QAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-01 18:20:04
(17 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack