🇩🇪
Phenix Info
2026-09-06 22:57:46
(3 hours ago)
SmallGuard.fr/Prestashop Empty User Agent
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-06 22:10:55
(4 hours ago)
[Mon Sep 07 08:10:54.292575 2026] [security2:error] [pid 31269] [client 34.106.253.91:40736] [client ...
show more
[Mon Sep 07 08:10:54.292575 2026] [security2:error] [pid 31269] [client 34.106.253.91:40736] [client 34.106.253.91] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dance4fitness.com.au"] [uri "/.git/config"] [unique_id "ap3k7hXrfENpv1HDxM8xRgAAAAo"]
...
show less
Web App Attack
🇩🇪
iNetWorker
2026-09-06 21:45:07
(4 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:10:56
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:10:50.225990 2026] [security2:error] [pid 18811:tid 18811] [client 34.106.253.91:35300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jennyfiore.com"] [uri "/.git/config"] [unique_id "ap3W2kALq_bGrbb2Dldi-wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:53:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:52:57.773537 2026] [security2:error] [pid 5010:tid 5010] [client 34.106.253.91:42556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celebritybikinigossip.com"] [uri "/.git/config"] [unique_id "ap3SqU2CsL-huAGIN5wrQAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
CBJ
2026-09-06 20:26:00
(5 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇫🇮
cleverest.eu
2026-09-06 20:14:34
(6 hours ago)
MimirWAF has 1 incident from 1 distinct domain => {"bad_request_uri / vcs_probe"}
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:04:31
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:04:23.486496 2026] [security2:error] [pid 21841:tid 21841] [client 34.106.253.91:54478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "havenlaneministries.com"] [uri "/.git/config"] [unique_id "ap3HR3n2e2V67RlAFXRCVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 19:38:56
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-06 21:33:57,298 fail2ban.filter [2048]: INFO [plesk-apache] ...
show more
cloudlinux2 fail2ban: 2026-09-06 21:33:57,298 fail2ban.filter [2048]: INFO [plesk-apache] Found 104.248.174.168 - 2026-09-06 21:33:57cloudlinux2 fail2ban: 2026-09-06 21:34:17,142 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 136.144.33.51 - 2026-09-06 21:34:16cloudlinux2 fail2ban: 2026-09-06 21:35:59,631 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.106.253.91 - 2026-09-06 21:35:59cloudlinux2 fail2ban: 2026-09-06 21:38:00,709 fail2ban.actions [2048]: NOTICE [plesk-modsecurity] Ban 35.244.20.96cloudlinux2 fail2ban: 2026-09-06 21:38:00,632 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.244.20.96 - 2026-09-06 21:38:00cloudlinux2 fail2ban: 2026-09-06 21:38:00,716 fail2ban.filter [2048]: INFO [recidive] Found 35.244.20.96 - 2026-09-06 21:38:00cloudlinux2 fail2ban: 2026-09-06 21:38:00,097 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 35.244.20.96 - 2026-09-06 21:38:00cloudlinux2 fail2ban: 2026-09-06 21:3
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:31:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.253.91 (91.253.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:31:10.133746 2026] [security2:error] [pid 9650:tid 9650] [client 34.106.253.91:60148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abcollie.com"] [uri "/.git/config"] [unique_id "ap2_fnzsw_BbLyIbDx7hhAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 19:25:54
(6 hours ago)
34.106.253.91 - - [06/Sep/2026:19:25:53 +0000] "GET /.git/config HTTP/1.1" 404 51576 "-" "-"
...
Bad Web Bot
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-06 19:16:28
(7 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
joharikop
2026-09-06 19:10:03
(7 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
🇫🇷
MatStef132
2026-09-06 18:37:57
(7 hours ago)
MatShield L7: blocked on mathost.eu (secret-path-probe)
DDoS Attack
Anonymous
2026-09-06 18:37:03
(7 hours ago)
apache vulnerability scan
Web App Attack