๐บ๐ธ
TPI-Abuse
2026-09-28 19:39:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:39:39.729996 2026] [security2:error] [pid 4050:tid 4050] [client 34.143.191.9:33950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internetnameregistration.com"] [uri "/.git/config"] [unique_id "arrCe469GM9iEHwkddTOlAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-28 02:35:08
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 19:23:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 15:23:20.219634 2026] [security2:error] [pid 24648:tid 24648] [client 34.143.191.9:34062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.techimprints.com"] [uri "/.git/config"] [unique_id "arltKL61lhRfhX5l7ws-CgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
habs
2026-09-27 15:40:58
(1 day ago)
34.143.191.9 - - [27/Sep/2026:18:40:58 +0300] "GET /wp-admin/phpinfo.php HTTP/1.1" 200 2591 "-" "Moz ...
show more
34.143.191.9 - - [27/Sep/2026:18:40:58 +0300] "GET /wp-admin/phpinfo.php HTTP/1.1" 200 2591 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-27 15:40:10
(1 day ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ง๐ท
dermatovirtual
2026-09-27 09:20:48
(1 day ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 25 unauthorized requests recorded between 2026-09-26 09:18:40 UTC and 2026-09-26 09:18:49 UTC (rate: ~25 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env1 -> HTTP 404 [CLIENT: 34.143.191.9]
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env.dist -> HTTP 404 [CLIENT: 34.143.191.9]
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env.swp -> HTTP 404 [CLIENT: 34.143.191.9]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:14:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:14:43.215545 2026] [security2:error] [pid 3414:tid 3414] [client 34.143.191.9:33334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canfieldnyc.com"] [uri "/.git/config"] [unique_id "argnswwb-VxkSGsfTEsVWwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:47:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:47:46.903183 2026] [security2:error] [pid 10571:tid 10571] [client 34.143.191.9:58908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.opennatura.com"] [uri "/.git/config"] [unique_id "arfpIkrBhQQD404s349WsAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:21:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.191.9 (9.191.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:21:41.322032 2026] [security2:error] [pid 26980:tid 26980] [client 34.143.191.9:38770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.openheartwellness.com"] [uri "/.git/config"] [unique_id "arfjBRnsvdiHJO-5m3852wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
dermatovirtual
2026-09-26 09:20:45
(2 days ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 25 unauthorized requests recorded between 2026-09-26 09:18:40 UTC and 2026-09-26 09:18:49 UTC (rate: ~25 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env1 -> HTTP 404 [CLIENT: 34.143.191.9]
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env.dist -> HTTP 404 [CLIENT: 34.143.191.9]
[2026-09-26 09:18:48 UTC] IP: 34.143.191.9 - W3C IIS (Port 443): GET /.env.swp -> HTTP 404 [CLIENT: 34.143.191.9]
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-26 06:45:03
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 05:51:09
(2 days ago)
[livebd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Examp ...
show more
[livebd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.143.191.9 - - [26/Sep/2026:07:50:52 +0200] "GET /.git/config HTTP/1.1" 404 2142 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 19:43:16
(3 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
masterguru
2026-09-25 02:12:09
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ฏ๐ต
bokumin.org
2026-09-24 17:17:01
(4 days ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/config"] [id "9491 ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/.git/config"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack