๐ฉ๐ช
LRob
2026-09-02 09:35:42
(6 minutes ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-02 09:35 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:38:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:38:33.582633 2026] [security2:error] [pid 24155:tid 24155] [client 34.175.140.89:36360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamlikeitmatters.whatifandwhynot.xyz"] [uri "/.git/config"] [unique_id "apfgiXeQoR_qZMd-3AvS2QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 08:35:01
(1 hour ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:05:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:05:30.183880 2026] [security2:error] [pid 1855:tid 1855] [client 34.175.140.89:50598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamingofatlantis.com"] [uri "/.git/config"] [unique_id "apfYyjxwJ7jJqiVM798QzQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 07:36:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:35:56.641252 2026] [security2:error] [pid 17166:tid 17166] [client 34.175.140.89:36422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamhome.dhappraisalservices.com"] [uri "/.git/config"] [unique_id "apfR3CLv0ohcTS2k_YkcNgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 05:08:30
(4 hours ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
dynamix
2026-09-02 04:26:49
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:24:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:24:20.455967 2026] [security2:error] [pid 30821:tid 30821] [client 34.175.140.89:36656] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbolen.com"] [uri "/.git/config"] [unique_id "apdstKS74T0D3hq1ZntlRwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:45:35
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:45:29.431068 2026] [security2:error] [pid 22789:tid 22789] [client 34.175.140.89:33052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drbbenefits.com"] [uri "/.git/config"] [unique_id "apdjmZbx3bF61pxuWZg7iwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:14:31
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.140.89 (89.140.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:14:25.753088 2026] [security2:error] [pid 26227:tid 26227] [client 34.175.140.89:50488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drayvian.com"] [uri "/.git/config"] [unique_id "apdcUQN7h8kPWmSr1tpVLQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-09-01 20:54:03
(12 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;N ...
show more
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;PHP Injection Attack: Variable Access Found;Remote Command Execution: Direct Unix Command Execution;Remote Command Execution: Unix Shell Expression Found;Restricted File Access Attempt;SQL Injection Attack: SQL function name detected;URL file extension is restricted by policy;
show less
Web App Attack
๐ฌ๐ง
OptimusGO
2026-09-01 20:49:03
(12 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-01 21:49:02 UTC
Log evidence:
34.175.140.89 - - [01/Sep/2026:21:48:50 +0100] "GET /.env.development HTTP/1.1" 502 552 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.175.140.89 - - [01/Sep/2026:21:48:50 +0100] "GET /.env.test HTTP/1.1" 502 552 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.175.140.89 - - [01/Sep/2026:21:48:50 +0100] "GET /.env.remote HTTP/1.1" 502 552 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
Brute-Force
๐ฉ๐ช
MBombeck
2026-09-01 20:47:04
(12 hours ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
Anonymous
2026-09-01 20:03:34
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-01 18:53:11
(14 hours ago)
20 attempts against mh-misbehave-ban on yeti
Brute-Force
Bad Web Bot
Web App Attack