Anonymous
2026-09-05 02:33:41
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
JCB
2026-09-04 21:45:00
(8 hours ago)
34.118.138.156 - - [05/Sep/2026:00:03:05 +0300] "GET /site/.git/config HTTP/1.1" 301 287 "-" "crusad ...
show more
34.118.138.156 - - [05/Sep/2026:00:03:05 +0300] "GET /site/.git/config HTTP/1.1" 301 287 "-" "crusader-worker/1.0"
34.118.138.156 - - [05/Sep/2026:00:03:05 +0300] "GET /wordpress/.git/config HTTP/1.1" 301 292 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
🇮🇹
CoreTech srl
2026-09-04 19:33:58
(10 hours ago)
cloudlinux2 fail2ban: 2026-09-04 21:29:54,553 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 21:29:54,553 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 5.196.194.156 - 2026-09-04 21:29:54cloudlinux2 fail2ban: 2026-09-04 21:29:54,541 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 57.128.200.130 - 2026-09-04 21:29:54cloudlinux2 fail2ban: 2026-09-04 21:30:50,391 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 167.17.71.189 - 2026-09-04 21:30:50cloudlinux2 fail2ban: 2026-09-04 21:30:49,301 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 164.68.100.166 - 2026-09-04 21:30:49cloudlinux2 fail2ban: 2026-09-04 21:31:10,034 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 104.196.43.199cloudlinux2 fail2ban: 2026-09-04 21:32:49,356 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 35.227.105.54cloudlinux2 fail2ban: 2026-09-04 21:33:04,586 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 35.229.147.95cloudlinux2 fail2ban: 2026-09-04 21:33:45,473 fail2ban.fil
show less
Brute-Force
Anonymous
2026-09-04 19:07:02
(10 hours ago)
Automated web scanner. Requested suspicious paths: /site/.git/config | /app/.git/config | /api/.git/ ...
show more
Automated web scanner. Requested suspicious paths: /site/.git/config | /app/.git/config | /api/.git/config | /www/.git/config | /htdocs/.git/config | /html/.git/config | /.git/config | /var/www/.git/config | /public/.git/config | /backend/.git/config | /src/.git/config, /wordpress/.git/config | /api/.git/config | /www/.git/config | /htdocs/.git/config | /html/.git/config | /.git/config | /var/www/.git/config | /public/.git/config | /backend/.git/config | /src/.git/config. UTC: 2026-09-04 18:09:45.
show less
Web App Attack
🇺🇸
mnsf
2026-09-04 18:05:30
(11 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇩🇪
itsolon
2026-09-04 13:38:15
(16 hours ago)
[04/Sep/2026:15:38:14 +0200] 178852909425.132500 34.118.138.156 46208 217.154.7.177 80
[04/Sep/2026: ...
show more
[04/Sep/2026:15:38:14 +0200] 178852909425.132500 34.118.138.156 46208 217.154.7.177 80
[04/Sep/2026:15:38:14 +0200] 178852909465.843880 34.118.138.156 46232 217.154.7.177 80
[04/Sep/2026:15:38:14 +0200] 178852909483.382353 34.118.138.156 46218 217.154.7.177 80
[04/Sep/2026:15:38:13 +0200] 178852909369.596663 34.118.138.156 34538 217.154.7.177 443
[04/Sep/2026:15:38:13 +0200] 178852909382.781821 34.118.138.156 34448 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-04 13:07:02
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /public/.git/config HTTP/1.1, GET /html/.git/config HTTP ...
show more
Bot / scanning and/or hacking attempts: GET /public/.git/config HTTP/1.1, GET /html/.git/config HTTP/1.1, GET /www/.git/config HTTP/1.1, GET /.git/config HTTP/1.1, GET /backend/.git/config HTTP/1.1, GET /var/www/.git/config HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-04 12:00:04
(17 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 11:56:41
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:56:34.105203 2026] [security2:error] [pid 30442:tid 30442] [client 34.118.138.156:55226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.luckydawgs.com"] [uri "/var/www/.git/config"] [unique_id "apqx8jW3d4PDLpS5_j4VGwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 11:24:27
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:34:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:34:31.195893 2026] [security2:error] [pid 21297:tid 21297] [client 34.118.138.156:51314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lubbockknights.com"] [uri "/app/.git/config"] [unique_id "appKVyn-0M1UV3JmOo34xAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:16:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:16:06.177168 2026] [security2:error] [pid 18690:tid 18690] [client 34.118.138.156:37044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stmaarten-boatcharters.com"] [uri "/backend/.git/config"] [unique_id "appGBoq9hj7mBkean_VkUQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:57:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:57:14.292870 2026] [security2:error] [pid 13170:tid 13170] [client 34.118.138.156:46242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fedeoliva.cl"] [uri "/src/.git/config"] [unique_id "apoXakm3RWEZN5zm8FoZbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 00:10:43
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.118.138.156 (156.138.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:10:35.986690 2026] [security2:error] [pid 21272:tid 21272] [client 34.118.138.156:48214] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "slapai.org"] [uri "/.git/config"] [unique_id "apoMe2YUqHjBWZVMbbK8cAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-03 20:22:13
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack