🇺🇸
Starburst SysOp Team
2026-09-06 08:55:24
(5 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-4)
Hacking
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-06 08:13:09
(6 hours ago)
34.13.167.132 - - [06/Sep/2026:04:13:08 -0400] "GET /.git/config HTTP/1.1" 404 4843 "-" "crusader-wo ...
show more
34.13.167.132 - - [06/Sep/2026:04:13:08 -0400] "GET /.git/config HTTP/1.1" 404 4843 "-" "crusader-worker/1.0"
34.13.167.132 - - [06/Sep/2026:04:13:08 -0400] "GET /src/.git/config HTTP/1.1" 404 4843 "-" "crusader-worker/1.0"
34.13.167.132 - - [06/Sep/2026:04:13:08 -0400] "GET /public/.git/config HTTP/1.1" 404 4843 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇩🇪
netclix.gr
2026-09-06 06:17:31
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.13.167.132 (132.167.13.34.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-06 05:04:08
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:04:04.701395 2026] [security2:error] [pid 15376:tid 15376] [client 34.13.167.132:58744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyberclubcoin.com.crazycoin.net"] [uri "/public/.git/config"] [unique_id "apz0RFMog8JwYaDqCkORGAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:29:06
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:29:03.057212 2026] [security2:error] [pid 17134:tid 17134] [client 34.13.167.132:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dentguyvt.com"] [uri "/.git/config"] [unique_id "apzsD9yNwXOiAbjljFWF5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:58:43
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:58:35.189615 2026] [security2:error] [pid 25529:tid 25529] [client 34.13.167.132:48462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sasquatchproductionsltd.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sasquatchproductionsltd.com"] [uri "/mysql.sql"] [unique_id "apzW26ceejE5Lk1P1vQG1wAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
✨
2026-09-06 02:17:10
(12 hours ago)
Domain : ptlls-train-the-trainer.co.uk
Rule : config
2026-09-06 02:16:08 ***hidden-privacy*** GET /. ...
show more
Domain : ptlls-train-the-trainer.co.uk
Rule : config
2026-09-06 02:16:08 ***hidden-privacy*** GET /.git/config - 443 - 34.13.167.132 HTTP/1.1 crusader-worker/1.0 - ptlls-train-the-trainer.co.uk 404 8 0 1477 112 799 - -
show less
Hacking
SQL Injection
🇫🇷
✨
2026-09-06 01:53:10
(12 hours ago)
Domain : thepearlisland.co.uk
Rule : config
2026-09-06 01:51:19 W3SVC570 PLESK72 79.171.34.94 GET /. ...
show more
Domain : thepearlisland.co.uk
Rule : config
2026-09-06 01:51:19 W3SVC570 PLESK72 79.171.34.94 GET /.git/config - 80 - 34.13.167.132 HTTP/1.1 crusader-worker/1.0 - - thepearlisland.co.uk 500 19 5 1381 103 459 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-05 23:27:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:27:23.497058 2026] [security2:error] [pid 28983:tid 28983] [client 34.13.167.132:42734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.usaenquirer.com"] [uri "/.htaccess"] [unique_id "apylWytXhxslDxjlPoMFkQAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 22:41:57
(15 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-05 21:36:36
(16 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:29:23
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:29:20.334344 2026] [security2:error] [pid 32662:tid 32662] [client 34.13.167.132:35916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "virtualvideo.org"] [uri "/public/.git/config"] [unique_id "apyJsMH3vCIKLkXZq5GCfwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:39:21
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.13.167.132 (132.167.13.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.13.167.132 (132.167.13.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:39:13.683891 2026] [security2:error] [pid 24311:tid 24311] [client 34.13.167.132:47126] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||markgebhard.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "markgebhard.net"] [uri "/dump.sql"] [unique_id "apx98RZLhN8Dgv596tzsZwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dpsbs
2026-09-05 11:25:22
(1 day ago)
url scanning on multiple public ips detected
Bad Web Bot