πΊπΈ
TPI-Abuse
2026-09-29 20:56:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:56:03.989238 2026] [security2:error] [pid 3838:tid 3863] [client 34.23.241.168:33064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "medicallawsuit.net.aafm.us"] [uri "/.git/config"] [unique_id "arwl4wjBvlkA4zycieQUrAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 01:39:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:39:02.282087 2026] [security2:error] [pid 9750:tid 9750] [client 34.23.241.168:33820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lakewoodranchhairsalon.com"] [uri "/.git/config"] [unique_id "arsWtoqNHjxd_-dgqmPtywAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 01:06:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:06:25.121893 2026] [security2:error] [pid 5445:tid 5445] [client 34.23.241.168:41446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lakeviewstudiopro.com"] [uri "/.git/config"] [unique_id "arsPERab8nDhP7X7ybIg2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 00:41:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 20:41:29.622872 2026] [security2:error] [pid 16385:tid 16385] [client 34.23.241.168:34334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lakeviewbewdley.com"] [uri "/.git/config"] [unique_id "arsJOUkyoNOcB7fTPKNM3AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-09-27 04:04:10
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
π©πͺ
grassau.com
2026-09-26 19:56:01
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.23.241.168 (US/United States/South C ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.23.241.168 (US/United States/South Carolina/North Charleston/168.241.23.34.bc.googleusercontent.com)
show less
SQL Injection
π©πͺ
mravb
2026-09-26 07:12:38
(4 days ago)
34.23.241.168 - - [26/Sep/2026:10:12:37 +0300] "GET /.git/config HTTP/1.1" 403 180 "-" "Mozilla/5.0 ...
show more
34.23.241.168 - - [26/Sep/2026:10:12:37 +0300] "GET /.git/config HTTP/1.1" 403 180 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
Anonymous
2026-09-25 19:56:54
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-25 19:41:30
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π«π·
Nop Nop
2026-09-25 06:35:24
(5 days ago)
CrowdSec ban: crowdsecurity/http-sensitive-files
Port Scan
Anonymous
2026-09-24 03:45:26
(6 days ago)
[ns31.kdns.gr] httpd-config-scan: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores.gr.l ...
show more
[ns31.kdns.gr] httpd-config-scan: sites=www.myrofores.gr; logs=/var/log/httpd/domains/myrofores.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
πΊπΈ
antlac1
2026-09-23 08:29:01
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-21 20:56:05
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 16:58:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.23.241.168 (168.241.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:58:45.187708 2026] [security2:error] [pid 439122:tid 439122] [client 34.23.241.168:48430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancyscafeandcatering.com"] [uri "/.git/config"] [unique_id "arFiRVk-PseW2Xm70CpN2QAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π―π΅
tttomomi
2026-09-21 14:47:25
(1 week ago)
Repeated probing for credential and configuration files, and for known webshell and remote-code-exec ...
show more
Repeated probing for credential and configuration files, and for known webshell and remote-code-execution endpoints, on our web server. Every request was refused with a 4xx status; none returned content. Paths probed: /.git/config, /.env, /.env.local.
show less
Web App Attack