๐ฉ๐ช
kivitendo.de
2026-08-01 04:31:01
(6 minutes ago)
[Sat Aug 01 06:31:06.786437 2026] [access_compat:error] [pid 187498:tid 187548] [client 34.148.8.63: ...
show more
[Sat Aug 01 06:31:06.786437 2026] [access_compat:error] [pid 187498:tid 187548] [client 34.148.8.63:22638] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/HEAD
[Sat Aug 01 06:31:06.787587 2026] [access_compat:error] [pid 187498:tid 187540] [client 34.148.8.63:22636] AH01797: client denied by server configuration: /var/www/kivitendo-erp/.git/config
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 04:24:19
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 00:24:13.276808 2026] [security2:error] [pid 111477:tid 111477] [client 34.148.8.63:48680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.masterpiecemorgans.com"] [uri "/.env.production"] [unique_id "am107T-w4pl5B2p8qwGvRwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-01 04:07:52
(29 minutes ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
ArturShelby
2026-08-01 04:02:32
(34 minutes ago)
Critical file access: /docker-compose.yml
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-01 03:59:11
(38 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.8.63 (US/United States/63.8.148. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.8.63 (US/United States/63.8.148.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-01 02:39:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 22:39:13.720897 2026] [security2:error] [pid 1623057:tid 1623057] [client 34.148.8.63:10268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.b2c-llc.com"] [uri "/.env.local"] [unique_id "am1cUetWJHounqCvD74YlQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-08-01 02:25:35
(2 hours ago)
CrowdSec detection | scenario: http-crawl-non_statics
Bad Web Bot
๐ซ๐ท
masterguru
2026-08-01 02:10:18
(2 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.148.8.63 (US/United States/63.8.14 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.148.8.63 (US/United States/63.8.148.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-01 01:31:59
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:31:53.009128 2026] [security2:error] [pid 1301887:tid 1301887] [client 34.148.8.63:12054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.greensealusa.com"] [uri "/.env"] [unique_id "am1MiUUWHEDlBUm4wnS_NQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-08-01 01:10:07
(3 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 01:09:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:09:37.159032 2026] [security2:error] [pid 11319:tid 11319] [client 34.148.8.63:5070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.fiberscribe.com"] [uri "/.env"] [unique_id "am1HUYT_rNbbFf9iAgQyYQAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-01 01:03:56
(3 hours ago)
cloudlinux2 fail2ban: 2026-08-01 02:58:55,339 fail2ban.filter [1838]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-01 02:58:55,339 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 91.193.232.81 - 2026-08-01 02:58:54cloudlinux2 fail2ban: 2026-08-01 03:01:38,543 fail2ban.filter [1838]: INFO [plesk-apache] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ban: 2026-08-01 03:01:38,538 fail2ban.filter [1838]: INFO [plesk-apache] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ban: 2026-08-01 03:01:39,030 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ban: 2026-08-01 03:01:39,020 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ban: 2026-08-01 03:01:39,050 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ban: 2026-08-01 03:01:39,083 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 34.148.8.63 - 2026-08-01 03:01:38cloudlinux2 fail2ba
show less
Web App Attack
๐ฌ๐ง
andypiper
2026-08-01 01:01:24
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 00:28:59
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.148.8.63 (63.8.148.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 20:28:52.685336 2026] [security2:error] [pid 1557482:tid 1557482] [client 34.148.8.63:11964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kemela.com"] [uri "/.env"] [unique_id "am09xCRZThYTqABLViX3UQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Dunham Support
2026-08-01 00:14:51
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.148.8.63 (US/United States/63.8.148. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.148.8.63 (US/United States/63.8.148.34.bc.googleusercontent.com)
show less
SQL Injection