๐ฉ๐ช
EGP Abuse Dept
2026-09-16 08:07:26
(6 hours ago)
Scanning for web/db/file exploits on www.e-learning-begeleiding-in-geld.nl
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 07:00:00
(7 hours ago)
Automated web attack from 34.150.19.80 against our web server.
165 malicious requests on 2026-09-16 ...
show more
Automated web attack from 34.150.19.80 against our web server.
165 malicious requests on 2026-09-16 (UTC), denied with HTTP 403.
Classified as: probing for pre-installed web shells.
Requested developer consoles and API descriptions (/actuator/, /_ignition/, swagger, /jolokia). None exist here; all denied 403.
Observed request: GET /_profiler/phpinfo (HTTP 403).
The source requested 165 distinct paths matching 8 distinct attack classes, consistent with an automated vulnerability scanner run against a broad template set.
Sample request: GET /tmp/phpinfo.php
Probed for: .git repository files, exposed .env files, configuration files, nonexistent/suspicious paths.
User-Agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36".
This host presented a browser User-Agent but did not load the image or the script referenced by the returned page, which a browser would have fetched automatically.
All timestamps are UTC.
show less
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-16 04:51:05
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-16 04:44:13
(9 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:53:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:53:26.552470 2026] [security2:error] [pid 2684:tid 2684] [client 34.150.19.80:34044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myshineart.com.sobhrach.com"] [uri "/.git/config"] [unique_id "aqoEpqmcMjsKb-qkf5yI8QAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:01:19
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:01:12.828382 2026] [security2:error] [pid 24187:tid 24256] [client 34.150.19.80:54942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mysavvygourmet.meanmouse.com"] [uri "/.git/config"] [unique_id "aqn4aAwHPcdkUn4WKJbhfgAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 00:37:15
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
MM-bot
2026-09-15 20:46:00
(17 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-09-15 22:46:00 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 20:06:08
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:06:00.411279 2026] [security2:error] [pid 29587:tid 29587] [client 34.150.19.80:35758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myouenji.ichi51e.net"] [uri "/.git/config"] [unique_id "aqmlKO7todxPDHtgT5KUogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 18:57:11
(19 hours ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐ณ๐ฑ
Alt255
2026-09-15 18:43:16
(19 hours ago)
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-13al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.150.19.80 - - [15/Sep/2026:20:43:15 +0200] "GET /.git/config HTTP/1.1" 301 447 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-15 12:35:31
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-09-15 06:14:04
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 05:09:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.19.80 (80.19.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:09:50.967768 2026] [security2:error] [pid 5961:tid 5961] [client 34.150.19.80:59292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.friendlyfarm4fun.daisydoesoap.com"] [uri "/.git/config"] [unique_id "aqjTHsq4F1dya5LTAbHHWAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 04:00:25
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack