🇳🇱
Site.eu
2026-09-07 04:11:15
(5 minutes ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 03:52:53
(23 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:52:48.565850 2026] [security2:error] [pid 30097:tid 30097] [client 34.165.168.123:39938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caravaningfigaro.com"] [uri "/.git/config"] [unique_id "ap41EJ7q6kGNvduncdOJ_wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-07 03:30:17
(46 minutes ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 03:20:03
(56 minutes ago)
| [Dangerous/Israel] Aggressive IP 34.165.168.123 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Israel] Aggressive IP 34.165.168.123 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
🇫🇷
Nop Nop
2026-09-06 23:31:12
(4 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
🇫🇷
Octopuce
2026-09-06 21:35:36
(6 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:34:21
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:34:17.331191 2026] [security2:error] [pid 10575:tid 10575] [client 34.165.168.123:43836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caquintet.com"] [uri "/.git/config"] [unique_id "ap3cWRM8q-W22eMqZ4BpcQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-06 20:37:20
(7 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/123.168.165.34.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/123.168.165.34.bc.googleusercontent.com
show less
Web App Attack
🇩🇪
Hans Wurst
2026-09-06 19:28:48
(8 hours ago)
Many 404-Error: Suspicion of URL-Fuzzing/Bot-Scan.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 18:43:19
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:43:12.992134 2026] [security2:error] [pid 10611:tid 10646] [client 34.165.168.123:58924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captechinc.com"] [uri "/.git/config"] [unique_id "ap20QMY133v_hiJwxW51EAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
tsZero
2026-09-06 18:33:16
(9 hours ago)
Scan example: path=/.git/config status=404
Hacking
🇺🇸
TPI-Abuse
2026-09-06 17:45:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:45:11.429043 2026] [security2:error] [pid 19995:tid 20000] [client 34.165.168.123:48760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "captainpurpleproductions.com"] [uri "/.git/config"] [unique_id "ap2mp3h7K9gCPlF5lDPVpgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-06 17:33:27
(10 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:20:24
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.165.168.123 (123.168.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:20:16.162018 2026] [security2:error] [pid 9620:tid 9620] [client 34.165.168.123:52622] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "captaincookfj.com"] [uri "/.git/config"] [unique_id "ap2g0IiehMN8JjU8ltjeyAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 16:26:55
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-06 16:26 UTC
show less
Hacking
Web App Attack