🇮🇹
VHosting
2026-09-07 18:45:03
(19 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-07 17:46:43
(1 hour ago)
1.120 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇺🇸
dot.mg
2026-09-07 17:15:25
(1 hour ago)
Scan of vulnerable files
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:30:39
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:30:32.333242 2026] [security2:error] [pid 19713:tid 19757] [client 34.17.183.113:38482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcmproductionsgroup.com"] [uri "/.git/config"] [unique_id "ap7mqGeAISeWoIQ_UMZkMQAAAY0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 15:47:41
(3 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:49:36
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:49:28.557991 2026] [security2:error] [pid 28678:tid 28678] [client 34.17.183.113:60068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcmillerjr.com"] [uri "/.git/config"] [unique_id "ap4KGLnMemHtENamN3FuRAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:06:55
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:06:48.315994 2026] [security2:error] [pid 14364:tid 14364] [client 34.17.183.113:38208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dci.legal.kountz.org"] [uri "/.git/config"] [unique_id "ap3yCFsFc3zQ9ATFfymFaQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
cleverest.eu
2026-09-06 23:00:33
(20 hours ago)
MimirWAF has 273 incidents from 1 distinct domain => {"bad_request_uri / vcs_probe","blacklisted_acc ...
show more
MimirWAF has 273 incidents from 1 distinct domain => {"bad_request_uri / vcs_probe","blacklisted_access / definite_repeat_offender"}
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-06 22:53:23
(20 hours ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
Octopuce
2026-09-06 22:45:24
(20 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:36:48
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.17.183.113 (113.183.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.183.113 (113.183.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:36:44.382983 2026] [security2:error] [pid 10507:tid 10507] [client 34.17.183.113:55568] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dcagroupusa.com"] [uri "/.git/config"] [unique_id "ap2WnLBvtS-z_XceXprpIAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
hmt
2026-09-06 16:13:27
(1 day ago)
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.git/config HTTP/1.1" 404 181 "-" "Mozilla/5.0 ...
show more
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.git/config HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" host="dca.hmt.ovh"
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.env HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" host="dca.hmt.ovh"
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.env.local HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" host="dca.hmt.ovh"
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.env.production HTTP/1.1" 404 181 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" host="dca.hmt.ovh"
34.17.183.113 - - [06/Sep/2026:18:13:26 +0200] "GET /.env.staging HTTP/1.1" 404 181 "-" "Mozilla/5.0
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:53:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.183.113 (113.183.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:53:41.561872 2026] [security2:error] [pid 17964:tid 17964] [client 34.17.183.113:46422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dc406.net"] [uri "/.git/config"] [unique_id "ap1-dSambFuwOJaO4Dqa4QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
abuseiphack
2026-09-06 14:53:07
(1 day ago)
Automatic report for brute force attack
Bad Web Bot
🇺🇸
MPL
2026-09-06 14:52:34
(1 day ago)
tcp/443 (2 or more attempts)
Port Scan