🇺🇸
TPI-Abuse
2026-09-07 23:04:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:04:18.215727 2026] [security2:error] [pid 27968:tid 28018] [client 34.174.248.199:60960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leaderoftheopposition.com"] [uri "/.git/config"] [unique_id "ap9C8nKjLFBt42TlqlxHTAAAAlI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 17:35:29
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇷
Octopuce
2026-09-07 06:46:47
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇳🇱
Site.eu
2026-09-07 04:43:30
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
ambor
2026-09-07 04:10:42
(2 days ago)
L0ss Honeypot: Git configuration file access attempt. Path: /.git/config
Web App Attack
🇵🇱
Budyn
2026-09-07 03:00:12
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: l.budyn.wtf | URI: /.git/config | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-09-07 02:22:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (US/United States/199.248.174.34 ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (US/United States/199.248.174.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:48:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:48:31.742862 2026] [security2:error] [pid 18886:tid 18886] [client 34.174.248.199:60002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drwolberg.com"] [uri "/.git/config"] [unique_id "ap2ZX4NzDuIThZ9xfDHJSgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-06 15:55:32
(2 days ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 03:16:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.174.248.199 (199.248.174.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:16:25.878212 2026] [security2:error] [pid 21545:tid 21545] [client 34.174.248.199:48892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kaylamaclaincounseling.com"] [uri "/.git/config"] [unique_id "apzbCVTTV-rtZ76dfppg0AAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 01:38:57
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-06 01:38 UTC
show less
Hacking
Web App Attack
🇫🇮
pixiekat
2026-09-05 23:13:37
(3 days ago)
[Sun Sep 06 00:13:36.413437 2026] [security2:error] [pid 1158:tid 1235] [client 34.174.248.199:48728 ...
show more
[Sun Sep 06 00:13:36.413437 2026] [security2:error] [pid 1158:tid 1235] [client 34.174.248.199:48728] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "katy.devilishseraph.net"] [uri "/"] [unique_id "apyiIISBYikV4iHvZP-HAgAAAFU"]
[Sun Sep 06 00:13:36.850626 2026] [security2:error] [pid 1138:tid 1249] [client 34.174.248.199:48738] ModSecurity: Access denied with code 403 (phase 1). Pattern match ".+" at REQUEST_HEADERS:Next-Action. [file "/mnt/HC_Volume_105148208/crs/crs-custom.conf"] [line "166"] [id "9000100"] [msg "Next.js Server Action probe blocked (no Next.js apps on this server)"] [tag "custom/next-action-recon"] [hostname "katy.devilishseraph.net"] [uri "/"] [unique_id "apyiIF9f5-ByoXuB3QGLBwAAAAM"]
[Sun Sep 06 00:13:37.291532
...
show less
Web App Attack
🇺🇸
mnsf
2026-09-05 23:05:50
(3 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇵🇱
strefapi_com
2026-09-05 18:35:39
(3 days ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇳🇱
Savvii
2026-09-05 17:29:44
(3 days ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack