🇫🇷
SpaceHost-Server
2026-09-12 22:18:59
(29 minutes ago)
Brute-Force
Web App Attack
🇫🇷
Feelautom
2026-09-12 12:44:52
(10 hours ago)
[FeelAutom Auto-Ban] PathScan: /.env.backup (Score: 200)
Port Scan
🇩🇪
macrob
2026-09-12 12:22:32
(10 hours ago)
2026/09/12 12:22:30 [error] 825895#825895: *4330951 access forbidden by rule, client: 34.18.6.27, se ...
show more
2026/09/12 12:22:30 [error] 825895#825895: *4330951 access forbidden by rule, client: 34.18.6.27, server: infinsa.com, request: "GET /.git/config HTTP/2.0", host: "infinsa.com"
2026/09/12 12:22:30 [error] 825895#825895: *4330970 access forbidden by rule, client: 34.18.6.27, server: infinsa.com, request: "GET /.env HTTP/2.0", host: "infinsa.com"
2026/09/12 12:22:31 [error] 825895#825895: *4330970 access forbidden by rule, client: 34.18.6.27, server: infinsa.com, request: "GET /.env.local HTTP/2.0", host: "infinsa.com"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:38:11
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:38:05.090758 2026] [security2:error] [pid 2883414:tid 2883414] [client 34.18.6.27:43426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinitynull.mindchill.net"] [uri "/.git/config"] [unique_id "aqU5nXFv2pRapSkpklsvEwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-12 10:54:31
(11 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:44:46
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:44:40.626638 2026] [security2:error] [pid 25168:tid 25168] [client 34.18.6.27:40444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinityartistsgroup.com"] [uri "/.git/config"] [unique_id "aqUtGOtfqJpDfFEF_QUSyAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 09:45:03
(13 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇩🇪
konseptit
2026-09-12 09:32:58
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.18.6.27 (QA/Qatar/27.6.18.34.bc.goog ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.18.6.27 (QA/Qatar/27.6.18.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-12 08:17:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:17:54.187789 2026] [security2:error] [pid 14016:tid 14016] [client 34.18.6.27:60894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infinite-a.com"] [uri "/.git/config"] [unique_id "aqUKshkNWcy1mkUHJZPPCQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 06:39:45
(16 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.infectionsinstitute.com; logs=/var/log/httpd/domains/in ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.infectionsinstitute.com; logs=/var/log/httpd/domains/infectionsinstitute.com.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:36:09
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:36:05.892820 2026] [security2:error] [pid 3230779:tid 3230784] [client 34.18.6.27:56728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "infectioncontrolsys.com"] [uri "/.git/config"] [unique_id "aqTy1TciDHybfFlEEz6CBwAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-12 05:27:54
(17 hours ago)
8.426 requests with url.path *.env
254 requests with url.path *credentials.json
Brute-Force
Bad Web Bot
🇩🇪
iNetWorker
2026-09-12 04:23:04
(18 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 04:11:17
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.6.27 (27.6.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:11:13.053174 2026] [security2:error] [pid 18684:tid 18684] [client 34.18.6.27:49552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "inetbrain.com"] [uri "/.git/config"] [unique_id "aqTQ4Rf4cCCbVPBO1zBuBQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
wbsouza
2026-09-12 03:36:20
(19 hours ago)
CrowdSec: crowdsecurity/http-admin-interface-probing — automated firewall drops on self-hosted IDS s ...
show more
CrowdSec: crowdsecurity/http-admin-interface-probing — automated firewall drops on self-hosted IDS sensor
show less
Hacking