๐ฟ๐ฆ
conure.sh
2026-10-05 19:16:34
(22 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 18:38:47
(23 hours ago)
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.148.238.72 - - [05/Oct/2026:20:38:35 +0200] "GET /.git/config HTTP/1.1" 404 7761 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 18:22:44
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 14:22:38.855369 2026] [security2:error] [pid 23242:tid 23242] [client 34.148.238.72:45226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pioneercanadian.com"] [uri "/.git/config"] [unique_id "asPq7revZ7YnDuP_6vZ9GgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 16:04:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 12:04:23.738649 2026] [security2:error] [pid 15043:tid 15043] [client 34.148.238.72:52452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.luxebikinis.com"] [uri "/.git/config"] [unique_id "asPKh4CWfM1a6X15xJ4TMgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-05 15:30:00
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 15:24:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 11:24:47.948710 2026] [security2:error] [pid 32045:tid 32045] [client 34.148.238.72:60422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.landeagle.com"] [uri "/.git/config"] [unique_id "asPBPz32c7L1brQvRoHHrwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-05 15:19:38
(1 day ago)
[MonOct0517:19:30.2136322026][security2:error][pid963485:tid963487][client34.148.238.72:0]ModSecurit ...
show more
[MonOct0517:19:30.2136322026][security2:error][pid963485:tid963487][client34.148.238.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"710\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.labaita-lanzo.it\"][uri\"/.git/config\"][unique_id\"asPAAp4gwD_CZCtkrISngwAAAAA\"]
show less
Hacking
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-05 15:12:00
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 15:06:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 11:06:55.153654 2026] [security2:error] [pid 3838:tid 3838] [client 34.148.238.72:52180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.km-herbs.com"] [uri "/.git/config"] [unique_id "asO9Dwx527GUkn5kntqOnQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-05 15:00:34
(1 day ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:51:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:51:24.510485 2026] [security2:error] [pid 31318:tid 31318] [client 34.148.238.72:41500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.kavahawaii.com"] [uri "/.git/config"] [unique_id "asO5bJ3rFd3JBmx2a1RhzAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 14:36:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.238.72 (72.238.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 10:36:06.494335 2026] [security2:error] [pid 31652:tid 31652] [client 34.148.238.72:53130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.joukoji.com"] [uri "/.git/config"] [unique_id "asO11tAg3b5p7geMhTORZgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-04-25 16:55:55
(5 months ago)
NOQUEUE - IP: 34.148.238.72 - Apr 25 18:55:55 plesk postfix/smtpd[3716149]: NOQUEUE: reject: RCPT f ...
show more
NOQUEUE - IP: 34.148.238.72 - Apr 25 18:55:55 plesk postfix/smtpd[3716149]: NOQUEUE: reject: RCPT from 72.238.148.34.bc.googleusercontent.com[34.148.238.72]: 554 5.7.1 Service unavailable; Client host [34.148.238.72] blocked using dnsbl-2.uceprotect.net; Net 34.144.0.0/13 is UCEPROTECT-Level2 listed because 355 impacts are seen from GOOGLE-CLOUD-PLATFORM, US/AS396982 there. See: http://www.uceprotect.net/rblcheck.php?ipr=34.148.238.72; from=<> to=<REDACTED@REDACTED> proto=ESMTP helo=<[10.88.0.4]>
show less
Email Spam
๐ช๐ธ
librebit
2026-04-25 16:27:54
(5 months ago)
Listed IP in blacklist by postfix/dnsblog
Spoofing
๐ณ๐ฑ
Cloud86 B.V.
2026-04-25 16:26:06
(5 months ago)
categories: Email Spam
Email Spam