๐ณ๐ฑ
Savvii
2026-09-16 07:32:45
(3 days ago)
20 attempts against mh_ha-misbehave-ban on pf221113
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:20:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:20:16.310524 2026] [security2:error] [pid 17723:tid 17723] [client 34.131.185.244:40274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigislandhawaiirealestate.com"] [uri "/.git/config"] [unique_id "aqnSsLczNawrPE9-CeoY8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:38:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:38:21.879341 2026] [security2:error] [pid 17132:tid 17132] [client 34.131.185.244:36954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigheartskitchen.com"] [uri "/.git/config"] [unique_id "aqnI3YHw_JfS4p-USBZUCQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:15:25
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.185.244 (244.185.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:15:22.136061 2026] [security2:error] [pid 4567:tid 4567] [client 34.131.185.244:59650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigchus.com"] [uri "/.git/config"] [unique_id "aqmLOmwOoZXCAwZIJ1wZiQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-09-15 13:02:30
(4 days ago)
34.131.185.244 - - [15/Sep/2026:15:00:38 +0200] "GET /.git/config HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
34.131.185.244 - - [15/Sep/2026:15:00:38 +0200] "GET /.git/config HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "IN" "New Delhi" "28.63270" "77.21980"
34.131.185.244 - - [15/Sep/2026:15:00:38 +0200] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "IN" "New Delhi" "28.63270" "77.21980"
34.131.185.244 - - [15/Sep/2026:15:00:39 +0200] "GET /.env.local HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "IN" "New Delhi" "28.63270" "77.21980"
34.131.185.244 - - [15/Sep/2026:15:00:39 +0200] "GET /.env.production HTTP/1.1" 404 181 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "IN" "New Delhi" "28.63270" "77.21980"
...
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-15 11:56:51
(4 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.131.185.244 - - [15/Sep/2026:13:56:32 +0200] "GET /.git/config HTTP/1.1" 301 520 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-15 09:40:01
(4 days ago)
2026-09-15 11:38:00 GET /.git/config [404] && 2026-09-15 11:38:00 GET /.env [404] && 2026-09-15 11:3 ...
show more
2026-09-15 11:38:00 GET /.git/config [404] && 2026-09-15 11:38:00 GET /.env [404] && 2026-09-15 11:38:02 GET /.env.bak [404] && 140 more within 20 minutes
show less
Web App Attack
๐ซ๐ท
GabrielJST
2026-09-15 07:12:55
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.131.185.244 (IN/India/244.185.131.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.131.185.244 (IN/India/244.185.131.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
Anonymous
2026-09-15 05:45:02
(4 days ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 05:31:59
(4 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-15 05:19:51
(4 days ago)
Aggressive web scan
Web App Attack
๐ท๐บ
olegio
2026-09-15 05:02:37
(4 days ago)
34.131.185.244 - - [15/Sep/2026:05:02:36 +0000] "GET /.git/config HTTP/2.0" 403 168 "-" "Mozilla/5.0 ...
show more
34.131.185.244 - - [15/Sep/2026:05:02:36 +0000] "GET /.git/config HTTP/2.0" 403 168 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.131.185.244 - - [15/Sep/2026:05:02:37 +0000] "GET /.env HTTP/2.0" 403 168 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-15 03:45:13
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack