๐ณ๐ฑ
ItsJustStan
2026-09-16 16:56:05
(3 hours ago)
Web app attack - scanning for vulnerabilities
Web App Attack
๐ฉ๐ช
diosama
2026-09-16 15:26:13
(5 hours ago)
CrowdSec blocked: crowdsecurity/appsec-vpatch
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-16 15:02:18
(5 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 552 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:01:20
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:01:12.752699 2026] [security2:error] [pid 27125:tid 27125] [client 34.18.166.220:49398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homehealth101.com"] [uri "/.git/config"] [unique_id "aqqhKC4KllpL4OXpMlw9_AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
baphomet
2026-09-16 13:21:49
(7 hours ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-16T13:21:49Z sensor=fail2ban role=web-canary
src=34.18.166.220
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:54:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:54:08.251158 2026] [security2:error] [pid 5905:tid 5905] [client 34.18.166.220:57236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "homebuilt.org"] [uri "/.git/config"] [unique_id "aqqRcNiqUIGdgSb11x69RQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:51:01
(7 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:43:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:43:40.145488 2026] [security2:error] [pid 27837:tid 27837] [client 34.18.166.220:60384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hilltopfound.com"] [uri "/.git/config"] [unique_id "aqqA7MZFGnpFR38P2bT8-wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:40:09
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:40:03.509628 2026] [security2:error] [pid 25817:tid 25817] [client 34.18.166.220:47414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hills-tax.com"] [uri "/.git/config"] [unique_id "aqpyA28wqveyKLNckJasUgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 10:04:14
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:04:07.459600 2026] [security2:error] [pid 31399:tid 31399] [client 34.18.166.220:52914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillerhome.com"] [uri "/.git/config"] [unique_id "aqppl5RKRzkAqmQN5ZOjiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:32:40
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.166.220 (220.166.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:32:35.185602 2026] [security2:error] [pid 11873:tid 11873] [client 34.18.166.220:56560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillconsultants.alhill.com"] [uri "/.git/config"] [unique_id "aqpiM4WtN0I6H2fhj4w8LQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-16 08:40:23
(12 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
MSC IT for Business GmbH
2026-09-16 08:10:05
(12 hours ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-16 07:48:36
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 127
Exploited Host
Web App Attack
Anonymous
2026-09-16 04:38:12
(16 hours ago)
Bot / seems abusive / Apache connections: 69
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack