π©πͺ
FD-IX
2026-09-11 12:52:35
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-11 12:07:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:07:47.304492 2026] [security2:error] [pid 22981:tid 22981] [client 34.152.57.158:35306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ads.cruisingforsex.com"] [uri "/.git/config"] [unique_id "aqPvEyQiLEfnq6rT-wScZwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Victor LΓ³pez
2026-09-11 12:02:31
(2 hours ago)
ads.buscaempresas.co 34.152.57.158 - - [11/Sep/2026:07:02:30 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozi ...
show more
ads.buscaempresas.co 34.152.57.158 - - [11/Sep/2026:07:02:30 -0500] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
ads.buscaempresas.co 34.152.57.158 - - [11/Sep/2026:07:02:31 -0500] "POST / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
ads.buscaempresas.co 34.152.57.158 - - [11/Sep/2026:07:02:31 -0500] "POST / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
...
show less
Hacking
Web App Attack
π«π·
dynamix
2026-09-11 11:49:16
(2 hours ago)
Multiple WAF Violations
Web App Attack
π§πͺ
cmbplf
2026-09-11 11:28:49
(3 hours ago)
9.635 requests with url.path *.env
1.499 requests with url.path *phpinfo.php
251 requests with ur ...
show more
9.635 requests with url.path *.env
1.499 requests with url.path *phpinfo.php
251 requests with url.path *credentials.json
show less
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-11 10:43:18
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:43:13.234201 2026] [security2:error] [pid 25937:tid 25937] [client 34.152.57.158:60850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adrienberthaud.com"] [uri "/.git/config"] [unique_id "aqPbQRd4Q4FKW1nq8P8EFQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-11 08:50:03
(5 hours ago)
Excessive multi-domain requests
Brute-Force
π«π·
COMAITE
2026-09-11 08:47:33
(5 hours ago)
Suspicious URL access.
Web App Attack
π©πͺ
FeG Deutschland
2026-09-11 08:45:08
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
π©πͺ
LRob
2026-09-11 07:22:35
(7 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-11 07:22 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-11 06:50:21
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:50:16.206147 2026] [security2:error] [pid 24370:tid 24370] [client 34.152.57.158:52464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adorningmetal.com"] [uri "/.git/config"] [unique_id "aqOkqEEjTsrI9K0RA_1PyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
ππΊ
miszterx.hu
2026-09-11 06:29:34
(8 hours ago)
XORP (haproxy): 73x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 73x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
Anonymous
2026-09-11 06:15:02
(8 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-11 06:04:21
(8 hours ago)
Aggressive web scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-11 05:14:53
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.152.57.158 (158.57.152.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:14:45.833456 2026] [security2:error] [pid 5573:tid 5573] [client 34.152.57.158:52942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adona.org"] [uri "/.git/config"] [unique_id "aqOOReWJ1CJ6K1WbJjjPjQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack