🇮🇹
CoreTech srl
2026-09-12 10:08:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-12 12:04:19,511 fail2ban.actions [1606]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-12 12:04:19,511 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 34.32.137.90cloudlinux2 fail2ban: 2026-09-12 12:05:35,232 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 47.79.206.15 - 2026-09-12 12:05:34cloudlinux2 fail2ban: 2026-09-12 12:06:41,227 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.159.26.7 - 2026-09-12 12:06:41cloudlinux2 fail2ban: 2026-09-12 12:06:41,207 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.159.26.7 - 2026-09-12 12:06:41cloudlinux2 fail2ban: 2026-09-12 12:06:41,159 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.159.26.7 - 2026-09-12 12:06:41cloudlinux2 fail2ban: 2026-09-12 12:06:41,246 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.159.26.7 - 2026-09-12 12:06:41cloudlinux2 fail2ban: 2026-09-12 12:06:41,263 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 34.159.26.7 - 2026-09-12 12:06:41cloudlinux2 fail2ban: 2026-09
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-12 09:20:15
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:20:12.474078 2026] [security2:error] [pid 23830:tid 23830] [client 34.159.26.7:57592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bosdkbook.joepeters.org"] [uri "/.git/config"] [unique_id "aqUZTHsHH92S59gPSs14iAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 08:20:01
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 08:06:22
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:06:19.524359 2026] [security2:error] [pid 911:tid 911] [client 34.159.26.7:56120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "borzoi-pedigree.info"] [uri "/.git/config"] [unique_id "aqUH-xCw_qNTqMOPqNlFwwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 07:48:15
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+17 more) | 2026-09-12 07:48 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:46:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:46:11.821257 2026] [security2:error] [pid 32097:tid 32195] [client 34.159.26.7:59778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bortec-corp.com"] [uri "/.git/config"] [unique_id "aqUDQ7kT5d6bvLMEkfBhNAAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-12 07:43:18
(3 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-12 07:13:41
(4 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-12 06:13:54
(5 hours ago)
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.26.7 - - [12/Sep/2026:08:13:52 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.26.7
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-12 05:23:37
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇳🇱
debestelapp
2026-09-12 04:45:12
(6 hours ago)
Web App Attack
🇧🇪
cmbplf
2026-09-12 04:26:20
(7 hours ago)
11.444 requests with url.path *.env
1.884 requests with url.path *phpinfo.php
272 requests with u ...
show more
11.444 requests with url.path *.env
1.884 requests with url.path *phpinfo.php
272 requests with url.path *credentials.json
156 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-12 04:05:04
(7 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:28:45
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.26.7 (7.26.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:28:36.916780 2026] [security2:error] [pid 16980:tid 16980] [client 34.159.26.7:45240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bordwell.com"] [uri "/.git/config"] [unique_id "aqTG5Ah14tw91_8AydAq6wAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-12 03:26:12
(8 hours ago)
(modsecurity) srv102 ModSecurity 34.159.26.7 (DE/Germany/7.26.159.34.bc.googleusercontent.com): 30 i ...
show more
(modsecurity) srv102 ModSecurity 34.159.26.7 (DE/Germany/7.26.159.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack