๐จ๐ญ
YF
2026-09-29 14:30:38
(4 days ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ฉ๐ช
LRob
2026-09-29 07:20:30
(4 days ago)
Secret file probe | method: GET | path: /.git/config, /.env, /.env.local | ua: Mozilla/5.0 (X11; Lin ...
show more
Secret file probe | method: GET | path: /.git/config, /.env, /.env.local | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 07:11:04
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:10:57.078237 2026] [security2:error] [pid 17660:tid 17660] [client 34.104.132.27:43136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.emailaegis.axiomemail.net"] [uri "/.git/config"] [unique_id "artkgVXmwOQxqnpsoUyq-QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-28 23:35:17
(4 days ago)
701 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ฉ๐ช
marten_o
2026-09-28 04:08:40
(5 days ago)
34.104.132.27 - - [28/Sep/2026:06:08:39 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/ ...
show more
34.104.132.27 - - [28/Sep/2026:06:08:39 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 317 588
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 04:07:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 00:07:48.810048 2026] [security2:error] [pid 9370:tid 9370] [client 34.104.132.27:39558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ehrlichfamily.com.ehrlichmedia.com"] [uri "/.git/config"] [unique_id "arnoFH57XodqqIbunaRm8wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-27 19:19:54
(5 days ago)
(modsecurity) srv201 ModSecurity 34.104.132.27 (JP/Japan/27.132.104.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv201 ModSecurity 34.104.132.27 (JP/Japan/27.132.104.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 13:04:36
(6 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-26 12:50:22
(1 week ago)
(modsecurity) srv104 ModSecurity 34.104.132.27 (JP/Japan/27.132.104.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv104 ModSecurity 34.104.132.27 (JP/Japan/27.132.104.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 08:23:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.132.27 (27.132.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 04:23:52.143190 2026] [security2:error] [pid 1966:tid 1966] [client 34.104.132.27:52304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.exresearch.com.ieas.org"] [uri "/.git/config"] [unique_id "areBGN2Umosv24m5BxYisQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-25 10:41:13
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-25 08:23:01
(1 week ago)
[Fri Sep 25 18:23:01.096091 2026] [security2:error] [pid 604231] [client 34.104.132.27:41066] [clien ...
show more
[Fri Sep 25 18:23:01.096091 2026] [security2:error] [pid 604231] [client 34.104.132.27:41066] [client 34.104.132.27] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.furst.com.au"] [uri "/"] [unique_id "arYvZW9irYFENrY5sxL3vwAAAAM"]
...
show less
Web App Attack
Anonymous
2026-09-25 06:15:05
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:03:55
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-09-23 17:43:50
(1 week ago)
Excessive 404/403 errors
Brute-Force