๐ต๐ฑ
TaKeN
2026-08-31 11:04:00
(6 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-08-31T13:04:00+02:00 and 2026-08-31T13:04:00+02:00. Sample requested paths: /.env.save.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 10:28:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:28:51.334546 2026] [security2:error] [pid 25117:tid 25137] [client 34.175.4.145:44384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "e-dome.co.jp"] [uri "/.git/config"] [unique_id "apVXY7UG6raqrV2fM6X1mgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-31 09:58:04
(7 hours ago)
[31/Aug/2026:12:58:03 +0300] -- 34.175.4.145 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[31/Aug/2026:12:58:03 +0300] -- 34.175.4.145 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-31 08:30:36
(8 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
Baking333
2026-08-31 08:16:06
(9 hours ago)
[redacted] 34.175.4.145 - - [31/Aug/2026:09:16:04 +0100] "GET /.git/config HTTP/1.1" 302 6773 0/4853 ...
show more
[redacted] 34.175.4.145 - - [31/Aug/2026:09:16:04 +0100] "GET /.git/config HTTP/1.1" 302 6773 0/48530 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.175.4.145 - - [31/Aug/2026:09:16:05 +0100] "GET /.env HTTP/1.1" 302 1554 0/76201 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 07:40:44
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:40:40.543378 2026] [security2:error] [pid 12046:tid 12046] [client 34.175.4.145:41440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dyslexiaspecialistsonline.com"] [uri "/.git/config"] [unique_id "apUv-HeBuaB8t_2Wo8dxdgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-08-31 07:39:34
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.175.4.145 (ES/Spain/145.4.175.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.175.4.145 (ES/Spain/145.4.175.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
gadix
2026-08-31 07:01:22
(10 hours ago)
[31/Aug/2026:09:01:19.470742 +0200] apUmvxLicAYM45C60xvCXAAAAFA 34.175.4.145 41840 127.0.0.1 7081
[3 ...
show more
[31/Aug/2026:09:01:19.470742 +0200] apUmvxLicAYM45C60xvCXAAAAFA 34.175.4.145 41840 127.0.0.1 7081
[31/Aug/2026:09:01:19.636109 +0200] apUmvxLicAYM45C60xvCXgAAAFU 34.175.4.145 41856 127.0.0.1 7081
[31/Aug/2026:09:01:19.684990 +0200] apUmvybICfVPigA7p4YI_AAAABA 34.175.4.145 41866 127.0.0.1 7081
...
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-31 06:26:46
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
dynamix
2026-08-31 06:12:21
(11 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:14:03
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.175.4.145 (145.4.175.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:13:58.104084 2026] [security2:error] [pid 26067:tid 26067] [client 34.175.4.145:50258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dylanwalsh.net"] [uri "/.git/config"] [unique_id "apUNlnz7ZGbAI2b1l8GMGQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-31 04:38:51
(12 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-30 12:30:59
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-08-30 12:26:24
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐จ๐ฆ
Anytech
2026-08-30 11:28:53
(1 day ago)
Blocked by ConnMonitor
Web App Attack