Anonymous
2026-08-28 04:36:18
(3 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
mnsf
2026-08-28 00:06:37
(3 days ago)
Abuse Detected (18)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:30:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:30:37.333843 2026] [security2:error] [pid 9699:tid 9699] [client 34.148.126.246:54174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingerection.amazingwelding.com"] [uri "/.git/config"] [unique_id "apDInUETcX9GnaDePb7mugAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:31:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:31:32.584821 2026] [security2:error] [pid 26640:tid 26640] [client 34.148.126.246:33096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alwayswetandsexy.grayhost.net"] [uri "/.git/config"] [unique_id "apC6xMW5ktOqVjFOpDbBmgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 22:14:02
(3 days ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ช๐ธ
loadsoporte
2026-08-27 21:58:37
(3 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ซ๐ท
Little Iguana
2026-08-27 21:56:24
(3 days ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐ฆ๐บ
2000cn.com.au
2026-08-27 21:52:48
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 21:42:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:42:26.932921 2026] [security2:error] [pid 29355:tid 29355] [client 34.148.126.246:35436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altered-egos.com"] [uri "/.git/config"] [unique_id "apCvQkHiOG6zts1tQ-PkJwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
OK
2026-08-27 21:27:10
(3 days ago)
HTTP/HTTPS
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 21:25:18
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:23:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:23:11.268720 2026] [security2:error] [pid 28231:tid 28231] [client 34.148.126.246:46774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alsdepot.com"] [uri "/.git/config"] [unique_id "apCqv657jpXtsZeSEsplWwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-08-27 21:22:30
(3 days ago)
34.148.126.246 - - [27/Aug/2026:23:22:26 +0200] "GET /.git/config HTTP/1.1" 404 4622 "-" "-" 34.148. ...
show more
34.148.126.246 - - [27/Aug/2026:23:22:26 +0200] "GET /.git/config HTTP/1.1" 404 4622 "-" "-" 34.148.126.246 - - [27/Aug/2026:23:22:28 +0200] "GET /.git/config HTTP/1.1" 404 4622 "-" "-" 34.148.126.246 - - [27/Aug/2026:23:22:29 +0200] "GET /.git/config HTTP/1.1" 404 4622 "-" "-"
show less
Brute-Force
๐ช๐ธ
el-brujo
2026-08-27 21:08:46
(3 days ago)
27/Aug/2026:23:08:46.098866 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
27/Aug/2026:23:08:46.098866 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.148.126.246] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "alpine.elhacker.net"] [uri "/.git/config"] [unique_id "apCnXncrMk-RHASDotjNWAAAA-g"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 21:06:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.126.246 (246.126.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 17:05:58.430017 2026] [security2:error] [pid 29416:tid 29416] [client 34.148.126.246:57560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alphazeta.net"] [uri "/.git/config"] [unique_id "apCmttqlioNmbrmuXKrtJwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack