๐ฒ๐พ
Rizzy
2026-09-17 15:27:00
(21 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
pszsh
2026-09-17 15:03:00
(22 hours ago)
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sen ...
show more
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sensitive paths, e.g. /.git/config /.env /.env.local. Observed by an nginx reputation gate; no credentials or user data involved.
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 13:28:27
(23 hours ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.166.85.210 - - [17/Sep/2026:15:28:23 +0200] "GET /.git/config HTTP/1.1" 301 634 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 12:30:08
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 12:14:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:14:32.319711 2026] [security2:error] [pid 11293:tid 11293] [client 34.166.85.210:47280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crystaljohns.com"] [uri "/.git/config"] [unique_id "aqvZqJ2RaOgX80_a3ATYeAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 10:43:03
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-09-17 10:33:25
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 20:01:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:01:31.206471 2026] [security2:error] [pid 32169:tid 32169] [client 34.166.85.210:52534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kleens-uk.com"] [uri "/.git/config"] [unique_id "aqr1m61G8d8sl4ecOpXVSgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 18:11:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:11:36.978044 2026] [security2:error] [pid 19823:tid 19823] [client 34.166.85.210:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.kidswithcamerasmovie.com"] [uri "/.git/config"] [unique_id "aqrb2FGZXd6C6qtIT25S8QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:37:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:37:27.881081 2026] [security2:error] [pid 10845:tid 10845] [client 34.166.85.210:45912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.iconbizpromo.com"] [uri "/.git/config"] [unique_id "aqrT1wMQBOqqkriTFtoaQQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:54:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:54:27.704136 2026] [security2:error] [pid 4888:tid 4888] [client 34.166.85.210:46486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.hteca.com"] [uri "/.git/config"] [unique_id "aqrJw4fh8cDp2GuqluSbXgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-16 14:11:02
(1 day ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:37:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.166.85.210 (210.85.166.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:36:56.494039 2026] [security2:error] [pid 27998:tid 27998] [client 34.166.85.210:37440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.globalpackets.net"] [uri "/.git/config"] [unique_id "aqqNaG2pMpMdYo742p9GIQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
csirtsatc
2026-09-16 11:01:00
(2 days ago)
Request: /.env
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-16 10:00:33
(2 days ago)
[WedSep1612:00:27.5372442026][security2:error][pid408205:tid408322][client34.166.85.210:0]ModSecurit ...
show more
[WedSep1612:00:27.5372442026][security2:error][pid408205:tid408322][client34.166.85.210:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.jrtradeinnovation.ch\"][uri\"/.env.bak\"][unique_id\"aqpouzqpd4vEgEMm-mJaSQAAAM4\"]
show less
Port Scan
Brute-Force
Web App Attack