๐บ๐ธ
TPI-Abuse
2026-09-01 11:48:55
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.53.61 (61.53.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.53.61 (61.53.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:48:48.188116 2026] [security2:error] [pid 32118:tid 32118] [client 34.152.53.61:53566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anatolyaleksin.com"] [uri "/.git/config"] [unique_id "apa7oND2dHQ3tyxq1_0ovAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 10:49:18
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:55:26
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.53.61 (61.53.152.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.53.61 (61.53.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:55:21.556068 2026] [security2:error] [pid 5431:tid 5431] [client 34.152.53.61:57002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anamericanabroad.com"] [uri "/.git/config"] [unique_id "apaS-Z_6FWBHqdhdkWoh-wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-01 08:50:55
(8 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
oralunal
2026-09-01 07:55:56
(9 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-09-01 06:54:06
(10 hours ago)
[Tue Sep 01 07:54:04.590668 2026] [security2:error] [pid 3285692:tid 3285733] [client 34.152.53.61:3 ...
show more
[Tue Sep 01 07:54:04.590668 2026] [security2:error] [pid 3285692:tid 3285733] [client 34.152.53.61:39762] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "analytics.spacecadetgrrl.me"] [uri "/"] [unique_id "apZ2jMk1UlIVv_DHPBlqrwAAAA0"]
[Tue Sep 01 07:54:05.163447 2026] [security2:error] [pid 3285622:tid 3285682] [client 34.152.53.61:43276] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "analytics.spacecadetgrrl.me"] [uri "/"] [unique_id "apZ2jYtxVV5SwSIMN-WZNAAAANA"]
[Tue Sep 01
...
show less
Web App Attack
๐ฉ๐ช
bluematrix
2026-09-01 06:25:50
(10 hours ago)
crowdsecurity/http-sensitive-files - Ip 34.152.53.61 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 34.152.53.61 performed 'crowdsecurity/http-sensitive-files' (5 events over 2.560231836s) at 2026-09-01 06:25:52.992825619 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-01 05:54:40
(11 hours ago)
CMS/framework probe: 34.152.53.61 - - [01/Sep/2026:07:54:39 +0200] "GET /.git/config HTTP/1.1" 444 0 ...
show more
CMS/framework probe: 34.152.53.61 - - [01/Sep/2026:07:54:39 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=CA
...
show less
Web App Attack
๐ฉ๐ช
jotoma.de
2026-09-01 05:13:08
(11 hours ago)
[Tue Sep 01 07:12:40.752761 2026] [authz_core:error] [pid 1518953:tid 1518984] [client 34.152.53.61: ...
show more
[Tue Sep 01 07:12:40.752761 2026] [authz_core:error] [pid 1518953:tid 1518984] [client 34.152.53.61:41130] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/.env
[Tue Sep 01 07:12:55.783189 2026] [authz_core:error] [pid 1518953:tid 1518988] [client 34.152.53.61:39632] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/tmp/.env
[Tue Sep 01 07:13:06.931430 2026] [authz_core:error] [pid 1518953:tid 1518994] [client 34.152.53.61:51468] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/app
...
show less
Web Spam
Brute-Force
๐ณ๐ฑ
Site.eu
2026-09-01 04:33:14
(12 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
cydit.eu
2026-09-01 04:04:13
(12 hours ago)
phpMyAdmin attack detected by fail2ban on thor.cydit.eu
Web App Attack
๐ฉ๐ช
zmobariz
2026-09-01 04:02:52
(12 hours ago)
Automated detection: repeated HTTP 4xx scan-burst against a public web endpoint.
Port Scan
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-01 04:00:13
(12 hours ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-01T03:50:38Z
Ray ID: a3414fd7fec8ab57
UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
XICTRON
2026-09-01 03:20:05
(13 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
alecj.com
2026-09-01 03:14:36
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack