๐ฆ๐บ
Klaverstyn
2026-08-31 06:28:02
(14 hours ago)
Excessive HTTP request rate
Web App Attack
Anonymous
2026-08-31 06:13:04
(14 hours ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
๐ฆ๐น
Renรฉ Hickersberger
2026-08-31 06:06:21
(14 hours ago)
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Windows NT 10.0; Win64; ...
show more
malicious bot detected: violations="hit-honeypot"; user_agent="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-08-31 05:16:11
(15 hours ago)
34.18.163.15 - - [31/Aug/2026:07:16:11 +0200] "GET /.git/config HTTP/1.1" 200 1562 "-" "Mozilla/5.0 ...
show more
34.18.163.15 - - [31/Aug/2026:07:16:11 +0200] "GET /.git/config HTTP/1.1" 200 1562 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "git.fomx.gay"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
pszsh
2026-08-31 05:08:00
(15 hours ago)
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sen ...
show more
Automated probing for exposed secrets and version-control internals: 3 requests for non-existent sensitive paths, e.g. /app/.env /apps/.env /api/.env. Observed by an nginx reputation gate; no credentials or user data involved.
show less
Web App Attack
๐บ๐ธ
infra-monitor
2026-08-31 05:00:05
(15 hours ago)
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-probing, crowdsecurity/http-se ...
show more
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-probing, crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
๐จ๐ญ
dalslab ltd
2026-08-31 04:52:34
(15 hours ago)
[31/Aug/2026:06:52:33 +0200] - 405 405 - POST https git.dalslab.com "/" [Client 34.18.163.15] [Lengt ...
show more
[31/Aug/2026:06:52:33 +0200] - 405 405 - POST https git.dalslab.com "/" [Client 34.18.163.15] [Length 0] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[31/Aug/2026:06:52:33 +0200] - 405 405 - POST https git.dalslab.com "/" [Client 34.18.163.15] [Length 0] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[31/Aug/2026:06:52:33 +0200] - 405 405 - POST https git.dalslab.com "/" [Client 34.18.163.15] [Length 0] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[31/Aug/2026:06:52:33 +0200] - 404 404 - GET https git.dalslab.com "/.git/config" [Client 34.18.163.15] [Length 11] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 19:08:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:08:48.330382 2026] [security2:error] [pid 2666362:tid 2666376] [client 34.18.163.15:56242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.fandgins.com"] [uri "/.git/config"] [unique_id "apR_wHqaE-_gNbrpwOSa4wAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 07:51:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:51:29.032650 2026] [security2:error] [pid 12775:tid 12775] [client 34.18.163.15:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.atlascoombs.com"] [uri "/.git/config"] [unique_id "apPhAcPVMTJNRPLOCL-K_wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-30 05:45:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-06-26 05:10:16
(2 months ago)
Automated WAF report: 125-150 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 02:42:56
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.163.15 (15.163.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 22:42:48.572676 2026] [security2:error] [pid 17303:tid 17303] [client 34.18.163.15:37742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "instituteofscience.com"] [uri "/.env.uat"] [unique_id "aj3nKDraBBbfA-mpY2uT7gAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-26 02:25:07
(2 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-26 01:38:01
(2 months ago)
Restricted File Access Attempt. Matched phrase ".env" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-25 23:40:59
(2 months ago)
Multiple WAF Violations
Web App Attack