๐บ๐ธ
TPI-Abuse
2026-09-16 02:46:24
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:46:18.794816 2026] [security2:error] [pid 2434:tid 2434] [client 34.131.23.106:52756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bawaselcenter.iahksa.com"] [uri "/.git/config"] [unique_id "aqoC-vGDRXbcdkJGrHdzZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-16 02:06:08
(19 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:17:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:17:50.695169 2026] [security2:error] [pid 27309:tid 27309] [client 34.131.23.106:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.forsaleincr.com"] [uri "/.git/config"] [unique_id "aqm1_rCfmg3TEsbvO3F_TgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:15:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:15:05.336202 2026] [security2:error] [pid 15476:tid 15476] [client 34.131.23.106:50416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "battlestem.com"] [uri "/.git/config"] [unique_id "aql9GT89PVqq974lzF1sPQAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 15:15:46
(1 day ago)
[ti-hosboov] Web exploit scanning: 9 suspicious requests detected by fail2ban jail <name>. Example: ...
show more
[ti-hosboov] Web exploit scanning: 9 suspicious requests detected by fail2ban jail <name>. Example: 34.131.23.106 - - \[15/Sep/2026:08:25:43 +0200\] "GET /.git/config HTTP/1.1" 404 2156 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
34.131.23.106 - - \[15/Sep/2026:08:25:43 +0200\] "GET /.env HTTP/1.1" 404 2156 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
34.131.23.106 - - \[15/Sep/2026:08:25:43 +0200\] "GET /.env.local HTTP/1.1" 404 2156 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
34.131.23.106 - - \[15/Sep/2026:08:25:43 +0200\] "GET /
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:14:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.23.106 (106.23.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:14:03.045610 2026] [security2:error] [pid 11695:tid 11695] [client 34.131.23.106:60530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fales-lorenz.net"] [uri "/.git/config"] [unique_id "aqj-SxxlZIJxCfo_oyPrdwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 08:03:05
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
BlueWire Hosting
2026-09-15 07:37:50
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 07:25:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-15 04:30:02
(1 day ago)
suspicious request in access.log
Web App Attack