🇳🇱
homeshowdomain.nl
2026-09-05 22:02:23
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇩🇪
SCHAPPY
2026-09-05 02:32:42
(1 day ago)
Brute-force attack to non-existent web resources, HTTP code 404.
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 20:40:01
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 20:04:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:04:37.583740 2026] [security2:error] [pid 7394:tid 7394] [client 8.234.198.157:42588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dunbeggan.com"] [uri "/site/.git/config"] [unique_id "apskVUUco26jTAcNdqGhKQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:15:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:15:31.076629 2026] [security2:error] [pid 16413:tid 16413] [client 8.234.198.157:44272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sydat.se"] [uri "/src/.git/config"] [unique_id "apsY03LfNVph6vo9Ry2TQAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:50:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:50:52.430409 2026] [security2:error] [pid 10415:tid 10415] [client 8.234.198.157:38990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.travelswithfriends.com"] [uri "/api/.git/config"] [unique_id "apsTDM9vm83jEzLG7RBBugAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
pltcldvlpr
2026-09-04 17:55:27
(1 day ago)
CMS/framework probe: 8.234.198.157 - - [04/Sep/2026:19:55:26 +0200] "GET /public/.git/config HTTP/1. ...
show more
CMS/framework probe: 8.234.198.157 - - [04/Sep/2026:19:55:26 +0200] "GET /public/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
🇩🇪
dave
2026-09-04 16:23:01
(1 day ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/vpatch-git-config observed_by=1_hosts hit_count=12 first_seen=2026-09-04T16:23:01Z last_seen=2026-09-04T16:23:01Z
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:47:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:47:37.795102 2026] [security2:error] [pid 12751:tid 12751] [client 8.234.198.157:33302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.myemail.navy"] [uri "/src/.git/config"] [unique_id "aproGXyiEn-6PiLK8XZ9SQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 15:34:20
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:48:05
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 12:13:24
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:56:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:56:15.281214 2026] [security2:error] [pid 22282:tid 22406] [client 8.234.198.157:52992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.adultbaja.com"] [uri "/.git/config"] [unique_id "apqx3-WFLdcH77Kdc5ANAAAAAkk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:20:42
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:21:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.234.198.157 (157.198.234.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:20:57.077802 2026] [security2:error] [pid 20428:tid 20428] [client 8.234.198.157:44128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bvi-boat-registration.com"] [uri "/app/.git/config"] [unique_id "app_aU1BCSR-b2Uk7lr5QQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack