๐บ๐ธ
TPI-Abuse
2026-09-03 20:31:32
(34 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:31:28.960658 2026] [security2:error] [pid 26222:tid 26222] [client 34.118.154.221:34006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sabbathseminars.net"] [uri "/.git/config"] [unique_id "apnZIATY7jv1oIxfHyVFugAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 18:15:03
(2 hours ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
consul.to
2026-09-03 16:37:53
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-09-03 16:25:38
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-03 16:05:55
(5 hours ago)
Scanning/Probing (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 12:18:05
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:18:01.027611 2026] [security2:error] [pid 26699:tid 26699] [client 34.118.154.221:50876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cossey.me"] [uri "/wordpress/.git/config"] [unique_id "aplleWPe1JjHs8F8Scx_LwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-03 12:11:18
(8 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 09:54:20
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:54:14.449162 2026] [security2:error] [pid 9818:tid 9818] [client 34.118.154.221:33840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lollytalk.com"] [uri "/htdocs/.git/config"] [unique_id "aplDxo__Y0rbQgEAkX8GvgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 08:35:45
(12 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-09-03 08:20:04
(12 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-03 07:56:15
(13 hours ago)
[site]:443 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /site/.git/config HTTP/1.1" 404 5031 ...
show more
[site]:443 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /site/.git/config HTTP/1.1" 404 5031 "-" "crusader-worker/1.0"
[site]:443 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /www/.git/config HTTP/1.1" 404 5030 "-" "crusader-worker/1.0"
[site]:443 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /public/.git/config HTTP/1.1" 404 5029 "-" "crusader-worker/1.0"
[site]:80 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /htdocs/.git/config HTTP/1.1" 301 554 "-" "crusader-worker/1.0"
[site]:80 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /app/.git/config HTTP/1.1" 301 548 "-" "crusader-worker/1.0"
[site]:80 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /.git/config HTTP/1.1" 301 540 "-" "crusader-worker/1.0"
[site]:80 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /backend/.git/config HTTP/1.1" 301 556 "-" "crusader-worker/1.0"
[site]:80 34.118.154.221 - - [03/Sep/2026:09:56:11 +0200] "GET /src/.git/config HTTP/1.1" 301 548 "-" "crusader-worker/
show less
Bad Web Bot
๐ฟ๐ฆ
conure.sh
2026-09-03 07:52:43
(13 hours ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-03 06:03:55
(15 hours ago)
cloudlinux2 fail2ban: 2026-09-03 07:59:00,898 fail2ban.filter [1472]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-03 07:59:00,898 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 185.94.33.124 - 2026-09-03 07:59:00cloudlinux2 fail2ban: 2026-09-03 08:00:32,732 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 116.212.133.58 - 2026-09-03 08:00:31cloudlinux2 fail2ban: 2026-09-03 08:03:22,202 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.118.154.221 - 2026-09-03 08:03:21cloudlinux2 fail2ban: 2026-09-03 08:03:22,162 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.118.154.221 - 2026-09-03 08:03:21cloudlinux2 fail2ban: 2026-09-03 08:03:22,180 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.118.154.221 - 2026-09-03 08:03:21cloudlinux2 fail2ban: 2026-09-03 08:03:22,219 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.118.154.221 - 2026-09-03 08:03:21cloudlinux2 fail2ban: 2026-09-03 08:03:22,623 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Ban 34.118.154.221cloudlinux2 fail2
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-03 05:25:03
(15 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 04:53:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.118.154.221 (221.154.118.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 00:53:55.984338 2026] [security2:error] [pid 9980:tid 9980] [client 34.118.154.221:44786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oscarssons.com"] [uri "/.git/config"] [unique_id "apj9YwOu3bSGUbVhevH5RQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack