🇺🇦
URAN Publishing Service
2026-09-20 15:09:38
(19 hours ago)
[20/Sep/2026:18:09:38 +0300] -- 34.17.96.81 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/c ...
show more
[20/Sep/2026:18:09:38 +0300] -- 34.17.96.81 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 11:05:12
(23 hours ago)
Bot / seems abusive / Apache connections: 21
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-20 10:49:21
(23 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
Anonymous
2026-09-20 07:55:50
(1 day ago)
GET /.git/config HTTP/1.1
...
Web App Attack
🇩🇪
FeG Deutschland
2026-09-19 13:34:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇨🇦
Anytech
2026-09-19 12:26:02
(1 day ago)
Blocked by ConnMonitor
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 12:21:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:20:57.947710 2026] [security2:error] [pid 31985:tid 31985] [client 34.17.96.81:49334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kahnengineering.com"] [uri "/.git/config"] [unique_id "aq5-KQqb65w-pk2hYsWWjgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-19 12:15:02
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-19 11:47:41
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-18 07:49:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 03:49:47.238314 2026] [security2:error] [pid 4227:tid 4227] [client 34.17.96.81:47306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doublenaughtspycar.com"] [uri "/.git/config"] [unique_id "aqztGz3jEVh79kt1M-rCywAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-18 07:15:23
(3 days ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-17 17:06:20
(3 days ago)
Multiple WAF Violations
Web App Attack
🇫🇮
robotstxt
2026-09-17 16:52:41
(3 days ago)
34.17.96.81 - - [17/Sep/2026:16:51:51 +0000] "GET /.env HTTP/1.1" 403 33028 "-" rt="1.259" "Mozilla/ ...
show more
34.17.96.81 - - [17/Sep/2026:16:51:51 +0000] "GET /.env HTTP/1.1" 403 33028 "-" rt="1.259" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.17.96.81" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.env" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="1.259"
34.17.96.81 - - [17/Sep/2026:16:51:53 +0000] "GET /.env.local HTTP/1.1" 403 33035 "-" rt="1.213" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.17.96.81" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/.env.local" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="1.212"
34.17.96.81 - - [17/Sep/2026:16:51:54 +0000] "GET /.env.production HTTP/1.1" 403 33038 "-" rt="1.232" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 16:06:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:06:02.853395 2026] [security2:error] [pid 26811:tid 26811] [client 34.17.96.81:48290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directnic.blog"] [uri "/.git/config"] [unique_id "aqwP6n9q2585ySIX3gZ5WQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-17 13:58:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.96.81 (81.96.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:58:48.147096 2026] [security2:error] [pid 1733:tid 1733] [client 34.17.96.81:38206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directcch.com"] [uri "/.git/config"] [unique_id "aqvyGKHt664HWArjg77ZZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack