๐ฉ๐ช
Hary74656
2026-09-19 18:26:16
(4 minutes ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
y: Acces ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
y: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 55)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "divisio.at"] [uri "/"] [unique_id "aq7TyEsdhGSiasHEXyO-GwAAAQ4"]
[Sat Sep 19 20:26:16.130408 2026] [security2:error] [pid 90126:tid 90223] [client 34.17.67.13:39046] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "divisio.at"] [uri "/"] [unique_id "aq7TyEsdhGSiasHEXyO-HAAAARI"]
show less
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-19 17:27:42
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 34.17.67.13 (IT/Italy/13.67.17.34.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.17.67.13 (IT/Italy/13.67.17.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
svr
2026-09-19 17:04:55
(1 hour ago)
HC-Flood Web Scanner
Web App Attack
๐ฉ๐ช
Nevermind
2026-09-19 13:33:46
(4 hours ago)
34.17.67.13 - - [19/Sep/2026:15:33:45 +0200] "GET /.git/config HTTP/1.1" 404 468 "-" "Mozilla/5.0 (X ...
show more
34.17.67.13 - - [19/Sep/2026:15:33:45 +0200] "GET /.git/config HTTP/1.1" 404 468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.67.13 - - [19/Sep/2026:15:33:46 +0200] "GET /.env HTTP/1.1" 404 468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.67.13 - - [19/Sep/2026:15:33:46 +0200] "GET /.env.local HTTP/1.1" 404 468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.67.13 - - [19/Sep/2026:15:33:46 +0200] "GET /.env.production HTTP/1.1" 404 468 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:19:52
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:19:49.276975 2026] [security2:error] [pid 13784:tid 13784] [client 34.17.67.13:59964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jpfamilyllc.com"] [uri "/.git/config"] [unique_id "aq5v1e_MRBJlHifcy8LsbAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 10:13:42
(8 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 08:59:40
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:59:35.778927 2026] [security2:error] [pid 26324:tid 26324] [client 34.17.67.13:33672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diveron.com"] [uri "/.git/config"] [unique_id "aq5O90r2E6OKKMWFFSk4xAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 08:55:31
(9 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-19 08:24:40
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.17.67.13 (IT/Italy/13.67.17.34.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.17.67.13 (IT/Italy/13.67.17.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
wbsouza
2026-09-19 03:27:20
(15 hours ago)
CrowdSec: infra/bad-path-probe โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฉ๐ช
FD-IX
2026-09-19 03:01:25
(15 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-19 02:03:12
(16 hours ago)
Bot / seems abusive / Apache connections: 23
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-19 01:35:40
(16 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-19 00:44:38
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.67.13 (13.67.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:44:30.973041 2026] [security2:error] [pid 20132:tid 20132] [client 34.17.67.13:40714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ditchthediaper.com"] [uri "/.git/config"] [unique_id "aq3a7ggp_typPF9FmbA7ggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-19 00:34:53
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack