Anonymous
2026-09-01 09:51:12
(4 hours ago)
Bot / seems abusive / Apache connections: 27
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 03:20:04
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:20:00.634769 2026] [security2:error] [pid 3601134:tid 3601243] [client 34.165.96.2:52184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmykdesign.com"] [uri "/.git/config"] [unique_id "apZEYIQnTEuflOaj-hQNrgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-01 01:54:30
(12 hours ago)
[TueSep0103:54:25.1846932026][security2:error][pid3499238:tid3499332][client34.165.96.2:0]ModSecurit ...
show more
[TueSep0103:54:25.1846932026][security2:error][pid3499238:tid3499332][client34.165.96.2:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"cmsolution.ch\"][uri\"/\"][unique_id\"apYwUevd4OXtrTn79-QjTwAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 01:49:45
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-01 01:15:50
(13 hours ago)
Web application attack detected.
Web App Attack
๐จ๐ญ
copestack
2026-08-31 16:00:04
(22 hours ago)
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ...
show more
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ov-4e5936.
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-31 13:18:47
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐น๐ท
ycoskun41
2026-08-31 12:44:55
(1 day ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:31:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:31:37.050120 2026] [security2:error] [pid 18607:tid 18607] [client 34.165.96.2:52584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cosentient.com"] [uri "/.git/config"] [unique_id "apV0KXJXpVkrRgR6CB4JBwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-31 11:13:58
(1 day ago)
cloudlinux2 fail2ban: 2026-08-31 13:09:26,303 fail2ban.filter [1605]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-31 13:09:26,303 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.36.8 - 2026-08-31 13:09:25cloudlinux2 fail2ban: 2026-08-31 13:09:54,678 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.54.126 - 2026-08-31 13:09:54cloudlinux2 fail2ban: 2026-08-31 13:10:14,016 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.47.229 - 2026-08-31 13:10:13cloudlinux2 fail2ban: 2026-08-31 13:10:34,869 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 104.207.61.242 - 2026-08-31 13:10:34cloudlinux2 fail2ban: 2026-08-31 13:10:33,173 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 151.123.177.197 - 2026-08-31 13:10:32cloudlinux2 fail2ban: 2026-08-31 13:10:36,894 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 217.181.92.81 - 2026-08-31 13:10:36cloudlinux2 fail2ban: 2026-08-31 13:10:33,876 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 45.3.55.255 - 2026-08-31 13:10:33cloudli
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 11:07:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:07:18.490028 2026] [security2:error] [pid 17814:tid 17814] [client 34.165.96.2:55390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "corstratinc.com"] [uri "/.git/config"] [unique_id "apVgZjXbFGZq2adwSCFecwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 10:30:02
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:57:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.165.96.2 (2.96.165.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:57:53.215307 2026] [security2:error] [pid 17263:tid 17263] [client 34.165.96.2:34448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "correlationdesign.com"] [uri "/.git/config"] [unique_id "apVQIa7mdBeKMJjt_XOwJwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-08-31 09:27:02
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-31 07:53:05
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot