🇺🇸
TPI-Abuse
2026-09-05 20:32:47
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:32:42.432599 2026] [security2:error] [pid 3216688:tid 3216688] [client 34.214.253.66:42290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.country.ic1.biz"] [uri "/.git/config"] [unique_id "apx8aliSgSPkkgc0rvcySAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-05 16:01:42
(20 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 11:02:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 07:02:35.662861 2026] [security2:error] [pid 19701:tid 19701] [client 34.214.253.66:53360] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegreatleapforward.com"] [uri "/.git/config"] [unique_id "apv2y49o9_ftBG4GS0Kp7AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-05 08:21:51
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇮🇹
CoreTech srl
2026-09-05 06:28:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-05 08:24:28,595 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-05 08:24:28,595 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 89.22.80.212 - 2026-09-05 08:24:28cloudlinux2 fail2ban: 2026-09-05 08:24:36,121 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 185.60.105.9 - 2026-09-05 08:24:35cloudlinux2 fail2ban: 2026-09-05 08:25:35,533 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 68.225.58.156 - 2026-09-05 08:25:35cloudlinux2 fail2ban: 2026-09-05 08:25:44,360 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 216.81.248.67 - 2026-09-05 08:25:44cloudlinux2 fail2ban: 2026-09-05 08:26:27,289 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 68.10.53.51 - 2026-09-05 08:26:27cloudlinux2 fail2ban: 2026-09-05 08:26:41,320 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.37 - 2026-09-05 08:26:40cloudlinux2 fail2ban: 2026-09-05 08:27:09,041 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.214.253.66 - 2026-09-05 08:27:08cloudlinu
show less
Web App Attack
🇧🇪
cmbplf
2026-09-05 04:22:30
(1 day ago)
1.884 requests with url.path *.env
252 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-04 22:00:58
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇩🇪
paissangroup
2026-09-04 18:16:55
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:46:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:46:43.037222 2026] [security2:error] [pid 31385:tid 31385] [client 34.214.253.66:36474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.corinthianscruise.bahamascruisersguide.com"] [uri "/.git/config"] [unique_id "app3Y7kmehhf4f9idgod7gAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 07:35:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-04 05:14:31
(2 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 3s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 21:26:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 34.214.253.66 (ec2-34-214-253-66.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:26:34.334282 2026] [security2:error] [pid 4339:tid 4339] [client 34.214.253.66:43432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hacemostuvideoia.com.verdadesreales.com"] [uri "/.git/config"] [unique_id "apnmCtcrxIn4rpCmvixfmwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 20:17:53
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-03 18:00:09
(2 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-03 17:41:16
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking