🇺🇸
Starburst SysOp Team
2026-09-05 11:07:37
(50 minutes ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-5)
Hacking
Bad Web Bot
🇫🇷
dynamix
2026-09-05 11:02:40
(55 minutes ago)
Multiple WAF Violations
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-05 05:13:30
(6 hours ago)
7 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-05 02:33:00
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:32:54.583057 2026] [security2:error] [pid 30324:tid 30324] [client 34.179.170.231:43790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.discountbusinessholidaycards.com"] [uri "/www/.git/config"] [unique_id "apt_VqTAIuSkjC294g5FDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
sernate
2026-09-05 02:32:59
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (DE/Germany/231.170.179.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (DE/Germany/231.170.179.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 01:56:35
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:56:28.521743 2026] [security2:error] [pid 13362:tid 13362] [client 34.179.170.231:33828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kitebeach.deubellzebub.com"] [uri "/site/.git/config"] [unique_id "apt2zGS-1ZbLea40N9TF1QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-05 01:34:32
(10 hours ago)
CrowdSec: crowdsecurity/http-probing (DE/AS396982)
Web App Attack
Hacking
🇨🇦
Anytech
2026-09-04 22:23:42
(13 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇫🇷
bazter.pro
2026-09-04 22:06:36
(13 hours ago)
Auto-Ban [2026-09-05 01:06:36]: CRITICAL: Exploit trap paths (24); DC: Google LLC [Paths: 12] | Deta ...
show more
Auto-Ban [2026-09-05 01:06:36]: CRITICAL: Exploit trap paths (24); DC: Google LLC [Paths: 12] | Details: Exploit trap paths: /backend/.git/config, /www/.git/config, /src/.git/config, /.git/config, /public/.git/config | Sensitive files/paths: /backend/.git/config, /www/.git/config, /src/.git/config, /.git/config, /public/.git/config | 404 errors (24): /var/www/.git/config, /html/.git/config, /site/.git/config, /public/.git/config, /wordpress/.git/config, /.git/config, /backend/.git/config, /api/.git/config, /src/.git/config, /app/.git/config (and 2 more)
show less
Web App Attack
Hacking
🇲🇾
Rizzy
2026-09-04 21:22:38
(14 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:20:08
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:20:04.985854 2026] [security2:error] [pid 12883:tid 12883] [client 34.179.170.231:47378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.mcthorpe.com"] [uri "/www/.git/config"] [unique_id "aps2BNc7pDbuvNfkkwo5UgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:04:15
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:04:09.198757 2026] [security2:error] [pid 28104:tid 28104] [client 34.179.170.231:44482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mailin.davisllp.com"] [uri "/app/.git/config"] [unique_id "apsySVQ8o-NU73sDUj2bSgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-04 18:59:24
(16 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇱
SysAdmin Dylan
2026-09-04 18:51:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (DE/Germany/231.170.179.34.bc.go ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (DE/Germany/231.170.179.34.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 13:40:08
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.179.170.231 (231.170.179.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:40:00.385531 2026] [security2:error] [pid 32183:tid 32183] [client 34.179.170.231:53234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bfpsamoa.com"] [uri "/var/www/.git/config"] [unique_id "aprKMAvb0YNLg5euaOhFiwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack