Anonymous
2026-09-12 01:07:30
(2 hours ago)
Web application attack detected.
Web App Attack
🇧🇪
cmbplf
2026-09-12 01:00:49
(2 hours ago)
235 requests with url.path */.git/config
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 23:51:09
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:51:03.098845 2026] [security2:error] [pid 2326:tid 2326] [client 164.92.174.95:34498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "criticalmassofficial.com"] [uri "/.git/config"] [unique_id "aqST5zAjQuCJt3aR8AEQIwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 23:28:06
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:27:57.650697 2026] [security2:error] [pid 967:tid 967] [client 164.92.174.95:43170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cristalsupermercado.gp.com.grupoporvenir.com"] [uri "/.git/config"] [unique_id "aqSOfZubE68T3K5jQ6N61QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-11 23:10:21
(4 hours ago)
Web scanning / probing for vulnerable paths | URL: //assets/server/php/ | Evidence: www.crisalidatou ...
show more
Web scanning / probing for vulnerable paths | URL: //assets/server/php/ | Evidence: www.crisalidatours.com 164.92.174.95 - - [12/Sep/2026:01:10:03 +0200] \"GET //assets/server/php/ HTTP/1.1\" 404 4024 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=DE | ASN: DIGITALOCEAN-ASN | Country: DE
show less
Port Scan
Web App Attack
Anonymous
2026-09-11 23:07:02
(4 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config | //alfacgiapi/perl.alfa. UTC: 2026- ...
show more
Automated web scanner. Requested suspicious paths: /.git/config | //alfacgiapi/perl.alfa. UTC: 2026-09-11 22:22:20.
show less
Web App Attack
🇺🇸
legionMCCXV
2026-09-11 22:51:10
(4 hours ago)
PHP/WordPress shell scanner on non-PHP site — repeated requests to .php paths returning 404.
Bad Web Bot
🇳🇱
javierin
2026-09-11 22:31:03
(5 hours ago)
164.92.174.95 - crianzahoy.javierin.com - - [11/Sep/2026:22:31:02 +0000] "GET / HTTP/1.1" 200 4385 " ...
show more
164.92.174.95 - crianzahoy.javierin.com - - [11/Sep/2026:22:31:02 +0000] "GET / HTTP/1.1" 200 4385 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
164.92.174.95 - crianzahoy.javierin.com - - [11/Sep/2026:22:31:02 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
Anonymous
2026-09-11 22:19:20
(5 hours ago)
18 hits, proto=tcp, ports=443,80
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-11 21:54:30
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:54:27.221102 2026] [security2:error] [pid 688156:tid 688156] [client 164.92.174.95:60392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crescentawards.armadillosigns.com"] [uri "/.git/config"] [unique_id "aqR4k-7n7PkFSBq3rwTDiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
creoline GmbH
2026-09-11 21:49:02
(5 hours ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 21:32:12
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:32:08.798939 2026] [security2:error] [pid 32168:tid 32168] [client 164.92.174.95:50484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "creektech.com"] [uri "/.git/config"] [unique_id "aqRzWDI4ZqZQMfBr79MR2AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 21:01:07
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 17:01:00.617458 2026] [security2:error] [pid 1818784:tid 1819538] [client 164.92.174.95:59012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "credit-card-cap.com"] [uri "/.git/config"] [unique_id "aqRsDGLPhJgtVadW5skUBwAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 20:55:03
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 19:06:07
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 164.92.174.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 15:06:03.208968 2026] [security2:error] [pid 29226:tid 29226] [client 164.92.174.95:35580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crearcuestionarios.com.creartest.com"] [uri "/.git/config"] [unique_id "aqRRG5LZmYF4X8jErImtlQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack