🇧🇾
lns.bz
2026-09-07 13:57:48
(6 hours ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 03:12:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-09-06 01:15:42
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇮🇩
penjaga BRIN
2026-09-05 07:00:37
(2 days ago)
Suspicious malicious activity
Hacking
🇲🇽
octageeks.com
2026-09-05 04:13:00
(2 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
Anonymous
2026-09-04 23:07:06
(2 days ago)
Automated web scanner. Requested suspicious paths: /wordpress/.git/config | /htdocs/.git/config | /b ...
show more
Automated web scanner. Requested suspicious paths: /wordpress/.git/config | /htdocs/.git/config | /backend/.git/config | /public/.git/config | /var/www/.git/config | /.git/config | /www/.git/config | /api/.git/config | /app/.git/config | /src/.git/config | /html/.git/config | /site/.git/config. UTC: 2026-09-04 22:53:11.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:19:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:19:14.114756 2026] [security2:error] [pid 8298:tid 8375] [client 34.182.142.209:39182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdumail.us"] [uri "/src/.git/config"] [unique_id "aptD4idJYu0S8RePPKmifgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 21:49:09
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:38:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:38:39.636013 2026] [security2:error] [pid 11357:tid 11357] [client 34.182.142.209:55582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.twccsolutions.com"] [uri "/html/.git/config"] [unique_id "aps6X73K4r5rPQJZdGVRvgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:22:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:22:43.079819 2026] [security2:error] [pid 21963:tid 21963] [client 34.182.142.209:49200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fussmail.com"] [uri "/html/.git/config"] [unique_id "aps2o2epvkatIndlSC1_0QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-04 21:02:02
(2 days ago)
[FriSep0423:01:59.5132222026][security2:error][pid672391:tid672463][client34.182.142.209:0]ModSecuri ...
show more
[FriSep0423:01:59.5132222026][security2:error][pid672391:tid672463][client34.182.142.209:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.special-home.ch\"][uri\"/app/.git/config\"][unique_id\"apsxxxLzhRA5F66zZcZ6KQAAAIY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:12:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:12:49.943427 2026] [security2:error] [pid 20303:tid 20303] [client 34.182.142.209:60924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toody.com"] [uri "/html/.git/config"] [unique_id "apsKIdyMOXaqvJSugUlfdwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:51:31
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:51:25.083516 2026] [security2:error] [pid 1789:tid 1789] [client 34.182.142.209:52422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyclingboardgames.net.ankitoner.com"] [uri "/wordpress/.git/config"] [unique_id "apr3DVDm1qsnWt-fOVerrAAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-04 16:21:25
(3 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:13:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.142.209 (209.142.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:13:50.095860 2026] [security2:error] [pid 26223:tid 26223] [client 34.182.142.209:53822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nedelam.com"] [uri "/var/www/.git/config"] [unique_id "apruPlV35iCywHWwD_UD4gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack