๐บ๐ธ
TPI-Abuse
2026-09-28 06:48:20
(23 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.101.162.82 (82.162.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.101.162.82 (82.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:48:15.787042 2026] [security2:error] [pid 29201:tid 29201] [client 34.101.162.82:59920] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.thebealcompany.net.armstrongenvironmental.com"] [uri "/.git/config"] [unique_id "aroNrwpLiuINa_33JlpxcQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-28 05:11:12
(2 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.101.162.82 - - [28/Sep/2026:07:11:00 +0200] "GET /.git/config HTTP/1.1" 200 1476 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-27 08:05:53
(23 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:35:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:35:42.052959 2026] [security2:error] [pid 16643:tid 16643] [client 34.101.162.82:45496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kozyramodularhomebuilder.com"] [uri "/.git/config"] [unique_id "argsnkBmMfVxRCQC_zMsjQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:57:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:57:54.459019 2026] [security2:error] [pid 16626:tid 16626] [client 34.101.162.82:55000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.angelaknightmusic.com"] [uri "/.git/config"] [unique_id "arfdct5oLXn_Gqy2FqL7mgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 14:41:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 10:41:20.469661 2026] [security2:error] [pid 17624:tid 17624] [client 34.101.162.82:53796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.angelabcomics.com"] [uri "/.git/config"] [unique_id "arfZkKiBLo3ryH9zm6PmCgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 09:51:33
(1 day ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 09:33:22
(1 day ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.101.162.82 - - [26/Sep/2026:11:33:07 +0200] "GET /.git/config HTTP/1.1" 301 623 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-26 09:20:46
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-25 08:08:56
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-25 06:59:49
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-25 04:07:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.162.82 (82.162.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 00:07:26.286190 2026] [security2:error] [pid 17072:tid 17072] [client 34.101.162.82:55852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.altruaglobalsolutions.com"] [uri "/.git/config"] [unique_id "arXzfuhay7chLwxr9qUzwwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 12:04:14
(4 days ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
wteiken
2026-09-23 11:49:15
(4 days ago)
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:12 -0400] "GET /.git/config HTTP/1.1" ...
show more
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:12 -0400] "GET /.git/config HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:13 -0400] "GET /.env HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:13 -0400] "GET /.env.local HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:13 -0400] "GET /.env.production HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
www.teiken.dev:443 34.101.162.82:52892 - - [23/Sep/2026:07:49:13 -0400] "GET /.env.staging HTTP/1.1"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 18:32:51
(5 days ago)
Multiple WAF Violations
Web App Attack