๐ฎ๐ฉ
Incidents Response Neptus Team
2026-09-29 19:47:00
(1 week ago)
Report Abuse IP
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:37:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:37:31.221408 2026] [security2:error] [pid 24269:tid 24269] [client 34.148.201.91:51092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kentuckyminiaturehorsebreeders.org"] [uri "/.git/config"] [unique_id "arwTe9q2-eDoxixiJFLH2wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-29 00:42:03
(1 week ago)
(modsecurity) srv103 ModSecurity 34.148.201.91 (US/United States/91.201.148.34.bc.googleusercontent. ...
show more
(modsecurity) srv103 ModSecurity 34.148.201.91 (US/United States/91.201.148.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 00:21:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:20:54.178533 2026] [security2:error] [pid 28282:tid 28282] [client 34.148.201.91:42016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.meierstavern.com"] [uri "/.git/config"] [unique_id "arsEZtZAGMqgyBxpa0r20gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 07:04:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.201.91 (91.201.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 03:04:51.216940 2026] [security2:error] [pid 27160:tid 27160] [client 34.148.201.91:53270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "outlet.kemela.com"] [uri "/.git/config"] [unique_id "aroRk-vxWC3v3MQq5obj7AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-28 06:58:22
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 470 hits.
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-27 07:55:13
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
COMAITE
2026-09-27 06:26:43
(2 weeks ago)
Suspicious URL access.
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 03:48:27
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ฒ๐พ
Rizzy
2026-09-25 19:42:08
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-09-25 05:39:58
(2 weeks ago)
http-sensitive-files - IP: 34.148.201.91 - time="2026-09-25T07:39:58+02:00" level=info msg="(555f66 ...
show more
http-sensitive-files - IP: 34.148.201.91 - time="2026-09-25T07:39:58+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.148.201.91 (US/396982) : 4h ban on Ip 34.148.201.91" module=db
show less
Web App Attack
๐ซ๐ท
Hippoline
2026-09-25 05:11:06
(2 weeks ago)
[Fri Sep 25 07:10:50.127372 2026] [authz_core:error] [pid 14842] [client 34.148.201.91:37732] AH0163 ...
show more
[Fri Sep 25 07:10:50.127372 2026] [authz_core:error] [pid 14842] [client 34.148.201.91:37732] AH01630: client denied by server configuration: /var/www/pferde.lu/web/cakephp
[Fri Sep 25 07:11:05.384225 2026] [authz_core:error] [pid 14893] [client 34.148.201.91:41736] AH01630: client denied by server configuration: /var/www/pferde.lu/web/phpinfo.php
[Fri Sep 25 07:11:05.490577 2026] [authz_core:error] [pid 14893] [client 34.148.201.91:41736] AH01630: client denied by server configuration: /var/www/pferde.lu/web/info.php
[Fri Sep 25 07:11:05.601015 2026] [authz_core:error] [pid 14893] [client 34.148.201.91:41736] AH01630: client denied by server configuration: /var/www/pferde.lu/web/php.php
[Fri Sep 25 07:11:05.709017 2026] [authz_core:error] [pid 14893] [client 34.148.201.91:41736] AH01630: client denied by server configuration: /var/www/pferde.lu/web/i.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Philister11
2026-09-25 02:26:08
(2 weeks ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (US/AS396982)
Web App Attack
Hacking
๐ฉ๐ช
FeG Deutschland
2026-09-25 01:49:14
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 06:25:11
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack