🇺🇸
TPI-Abuse
2026-09-20 20:33:24
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:33:18.002590 2026] [security2:error] [pid 28606:tid 28606] [client 34.18.159.33:51548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenvalley1.com"] [uri "/.git/config"] [unique_id "arBDDpJmUSKHQdBbSF92kQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 20:03:10
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:03:05.107407 2026] [security2:error] [pid 18322:tid 18322] [client 34.18.159.33:59114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenstatedvd.deluxeexpress.com"] [uri "/.git/config"] [unique_id "arA7-QhhtSvW-ZPJmxlM4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-20 19:20:36
(14 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-20 18:51:29
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-20 18:29:33
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 17:14:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:14:30.422985 2026] [security2:error] [pid 19220:tid 19220] [client 34.18.159.33:42924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenfrytech.net"] [uri "/.git/config"] [unique_id "arAUduHxYDaHwb2oztAXOwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 17:11:20
(16 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-20 17:00:05
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-20 16:40:52
(16 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
LRob
2026-09-20 16:35:17
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-20 16:35 UTC
show less
Hacking
Web App Attack
🇫🇮
paissangroup
2026-09-20 15:19:54
(18 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-20 14:45:04
(18 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 14:21:07
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.159.33 (33.159.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:21:00.168666 2026] [security2:error] [pid 5263:tid 5263] [client 34.18.159.33:45588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldcountrygermanamericanclub.org"] [uri "/.git/config"] [unique_id "aq_rzNRNiu0nwkCqlwkRMwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-20 13:51:21
(19 hours ago)
[cb-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.18.159.33 - - [20/Sep/2026:15:51:04 +0200] "GET /.env.txt HTTP/1.0" 200 1626 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-20 13:11:19
(20 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack