๐ณ๐ฑ
oisecnet
2026-09-24 21:02:32
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-24. 38 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-24. 38 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:53:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:53:11.847070 2026] [security2:error] [pid 3927:tid 3937] [client 34.185.236.31:52806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidchapa.com"] [uri "/.git/config"] [unique_id "arTW5-040VojfPXKyJACdwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-24 07:43:38
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.185.236 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.185.236.31 (DE/Germany/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.185.236.31 (DE/Germany/31.236.185.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 05:02:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:02:26.004709 2026] [security2:error] [pid 18147:tid 18147] [client 34.185.236.31:55844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cruanyes.com"] [uri "/var/www/.git/config"] [unique_id "arSu4sHY3pPSTZVjRMLDHAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:14:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:14:33.517663 2026] [security2:error] [pid 20799:tid 20799] [client 34.185.236.31:57016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.skintormint.com"] [uri "/wordpress/.git/config"] [unique_id "arR5eQdBlFhei934CKCbkQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:41:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:41:34.158512 2026] [security2:error] [pid 17029:tid 17029] [client 34.185.236.31:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.kidswithcamerasmovie.com"] [uri "/html/.git/config"] [unique_id "arRxvlyL_halAs6nVYA4wAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:41:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:41:49.060892 2026] [security2:error] [pid 17961:tid 17961] [client 34.185.236.31:37102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cortona.ws"] [uri "/backend/.git/config"] [unique_id "arRjva9EFdjN2PA29P0HxAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:02:43
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
rsa
2026-09-23 21:50:00
(2 days ago)
GET /api/.git/config HTTP/1.1
DDoS Attack
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:48:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:48:14.801662 2026] [security2:error] [pid 13871:tid 13895] [client 34.185.236.31:60768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "centurylink-sales.com"] [uri "/.git/config"] [unique_id "arQe7lYUJS46cPD8f5qJAAAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 17:18:46
(2 days ago)
[server.tmg.gr] httpd-config-scan: sites=www.cardioathena2021.gr,www.cardioathena2022.gr,www.cardioa ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.cardioathena2021.gr,www.cardioathena2022.gr,www.cardioathena2023.gr,www.cardioathena2024.gr; logs=/var/log/httpd/domains/cardioathena2021.gr.log,/var/log/httpd/domains/cardioathena2022.gr.log,/var/log/httpd/domains/cardioathena2023.gr.log; samples=/public/.git/config | /www/.git/config | /site/.git/config
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 16:35:05
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:58:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.185.236.31 (31.236.185.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:57:56.683145 2026] [security2:error] [pid 26874:tid 26874] [client 34.185.236.31:38680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brinkworthdungeon.brinkworthmodels.com"] [uri "/htdocs/.git/config"] [unique_id "arPo9LaCjMEluvvgbliFCgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 14:27:56
(2 days ago)
[ti-14al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-14al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 34.185.236.31 - - \[23/Sep/2026:16:27:44 +0200\] "GET /backend/.git/config HTTP/1.1" 301 5861 "-" "crusader-worker/1.0"
34.185.236.31 - - \[23/Sep/2026:16:27:44 +0200\] "GET /app/.git/config HTTP/1.1" 301 5861 "-" "crusader-worker/1.0"
34.185.236.31 - - \[23/Sep/2026:16:27:44 +0200\] "GET /htdocs/.git/config HTTP/1.1" 301 5861 "-" "crusader-worker/1.0"
34.185.236.31 - - \[23/Sep/2026:16:27:44 +0200\] "GET /var/www/.git/config HTTP/1.1" 301 5861 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-23 09:14:46
(2 days ago)
34.185.236.31 - - [23/Sep/2026:12:14:45 +0300] "GET /.git/config HTTP/2.0" 404 3685 "-" "crusader-wo ...
show more
34.185.236.31 - - [23/Sep/2026:12:14:45 +0300] "GET /.git/config HTTP/2.0" 404 3685 "-" "crusader-worker/1.0"
34.185.236.31 - - [23/Sep/2026:12:14:45 +0300] "GET /app/.git/config HTTP/2.0" 404 3688 "-" "crusader-worker/1.0"
...
show less
Web App Attack