๐ซ๐ท
masterguru
2026-09-11 15:26:03
(28 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-11 14:30:13
(1 hour ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 13:14:18
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.154.147.229 (229.147.154.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.147.229 (229.147.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:14:14.297331 2026] [security2:error] [pid 28557:tid 28557] [client 34.154.147.229:60566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "anamericanabroad.com"] [uri "/.git/config"] [unique_id "aqP-pvLvP6l8uXzYl97JPwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-11 13:08:57
(2 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
oralunal
2026-09-11 12:03:45
(3 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ซ๐ฎ
pixiekat
2026-09-11 10:47:53
(5 hours ago)
[Fri Sep 11 11:47:51.332917 2026] [security2:error] [pid 3689056:tid 3689127] [client 34.154.147.229 ...
show more
[Fri Sep 11 11:47:51.332917 2026] [security2:error] [pid 3689056:tid 3689127] [client 34.154.147.229:58352] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "analytics.spacecadetgrrl.me"] [uri "/"] [unique_id "aqPcV-QYqeMn262Zih1PAgAAAEA"]
[Fri Sep 11 11:47:52.014938 2026] [security2:error] [pid 3689055:tid 3689144] [client 34.154.147.229:58360] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "analytics.spacecadetgrrl.me"] [uri "/"] [unique_id "aqPcWIP_4tJiCZiN3jElTQAAAAc"]
[Fri Sep
...
show less
Web App Attack
๐ฉ๐ช
bluematrix
2026-09-11 10:12:44
(5 hours ago)
crowdsecurity/http-sensitive-files - Ip 34.154.147.229 performed 'crowdsecurity/http-sensitive-files ...
show more
crowdsecurity/http-sensitive-files - Ip 34.154.147.229 performed 'crowdsecurity/http-sensitive-files' (5 events over 730.004314ms) at 2026-09-11 10:12:45.017683815 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-11 09:35:31
(6 hours ago)
CMS/framework probe: 34.154.147.229 - - [11/Sep/2026:11:35:31 +0200] "GET /.git/config HTTP/1.1" 444 ...
show more
CMS/framework probe: 34.154.147.229 - - [11/Sep/2026:11:35:31 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=IT
...
show less
Web App Attack
๐ฌ๐ง
venus.launch.bz
2026-09-11 08:57:14
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.154.147.229 (IT/Italy/229.147.154.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.154.147.229 (IT/Italy/229.147.154.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
jotoma.de
2026-09-11 08:44:05
(7 hours ago)
[Fri Sep 11 10:43:50.459559 2026] [authz_core:error] [pid 2745155:tid 2745208] [client 34.154.147.22 ...
show more
[Fri Sep 11 10:43:50.459559 2026] [authz_core:error] [pid 2745155:tid 2745208] [client 34.154.147.229:40030] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/.env
[Fri Sep 11 10:43:58.255895 2026] [authz_core:error] [pid 2745155:tid 2745212] [client 34.154.147.229:42126] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/tmp/.env
[Fri Sep 11 10:44:04.944622 2026] [authz_core:error] [pid 2745154:tid 2745244] [client 34.154.147.229:32836] AH01630: client denied by server configuration: /var/www/analytics.jotoma.de/config/app
...
show less
Web Spam
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-11 08:20:02
(7 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-11 08:03:21
(7 hours ago)
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from IT.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-11T07:03:15Z
Ray ID: a394cfc2af060d6d
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ซ๐ท
cydit.eu
2026-09-11 07:19:56
(8 hours ago)
phpMyAdmin attack detected by fail2ban on thor.cydit.eu
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-11 06:25:15
(9 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
alecj.com
2026-09-11 06:18:29
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack