๐ฌ๐ง
AvonleaConsulting
2026-06-09 22:59:27
(3 days ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:41
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 15:14:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:14:15.784453 2026] [security2:error] [pid 3099:tid 3099] [client 34.150.22.132:59140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.westernmassaa.net"] [uri "/.git/config"] [unique_id "aigtx7o_g3cdonCaJ2AkOQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 14:41:03
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-09 11:42:40
(3 days ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:38:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:38:24.230912 2026] [security2:error] [pid 5628:tid 5628] [client 34.150.22.132:50118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flybits.co.uk"] [uri "/.git/config"] [unique_id "aiftIIUwBHbJQYy3WnoCfQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:52:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:52:53.521206 2026] [security2:error] [pid 18553:tid 18553] [client 34.150.22.132:37766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rblep.com"] [uri "/.git/config"] [unique_id "aifidb3fZ_72bSdStMi8tAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 08:07:53
(3 days ago)
[TueJun0910:07:51.2138942026][security2:error][pid2595528:tid2595643][client34.150.22.132:0]ModSecur ...
show more
[TueJun0910:07:51.2138942026][security2:error][pid2595528:tid2595643][client34.150.22.132:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"dsfiduciaria.ch\"][uri\"/.git/config\"][unique_id\"aifJ15-GcKG_7kxkVdhAiwAAAQ4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 07:44:17
(3 days ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.150.22.132 (HK/Hong Kong/132.22.15 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.150.22.132 (HK/Hong Kong/132.22.150.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 07:17:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:17:40.771568 2026] [security2:error] [pid 1875:tid 1875] [client 34.150.22.132:38424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mess.5995.us"] [uri "/.git/config"] [unique_id "aie-FN21S_AR0iBSbzkPeAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-09 07:03:09
(3 days ago)
(mod_security-custom) mod_security (id:210492) triggered by 34.150.22.132 (HK/Hong Kong/Kowloon/Hong ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 34.150.22.132 (HK/Hong Kong/Kowloon/Hong Kong/132.22.150.34.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
๐ฆ๐บ
MAGIC
2026-06-09 02:04:24
(3 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:04:08
(4 days ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 20:42:43
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:42:39.714981 2026] [security2:error] [pid 15833:tid 15833] [client 34.150.22.132:51480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sfprivatechef.noshsf.com"] [uri "/.git/config"] [unique_id "aicpP1UbrjY4u9ollwVb5gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:08:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.22.132 (132.22.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:08:05.593320 2026] [security2:error] [pid 4548:tid 4548] [client 34.150.22.132:46608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.shipdirect.gulftelecom.com"] [uri "/.git/config"] [unique_id "aicTFdZtIvHXpCm5AQPVAwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack