๐บ๐ธ
TPI-Abuse
2026-09-29 07:35:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.165.231 (231.165.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.165.231 (231.165.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 03:35:39.780110 2026] [security2:error] [pid 8075:tid 8075] [client 34.24.165.231:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr-online.com"] [uri "/.git/config"] [unique_id "artqS4qmHpIYaro_5ffSEwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-29 05:20:02
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-26 23:05:22
(2 days ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:02:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.165.231 (231.165.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.165.231 (231.165.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:02:11.284345 2026] [security2:error] [pid 11017:tid 11017] [client 34.24.165.231:59530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cns518.com"] [uri "/.git/config"] [unique_id "argkwyaNuShwk7uRcut5IgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 09:15:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-09-25 06:46:44
(4 days ago)
Scanning for web/db/file exploits on www.ogenblikjeoptiek.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-25 04:17:08
(4 days ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ณ๐ฑ
Mangelot Hosting
2026-09-24 03:27:37
(5 days ago)
(modsecurity) srv201 ModSecurity 34.24.165.231 (US/United States/231.165.24.34.bc.googleusercontent. ...
show more
(modsecurity) srv201 ModSecurity 34.24.165.231 (US/United States/231.165.24.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฆ๐น
piqwjdas
2026-09-24 02:25:24
(5 days ago)
{"transaction":{"client_ip":"34.24.165.231","time_stamp":"Thu Sep 24 04:25:23 2026","server_id":"468 ...
show more
{"transaction":{"client_ip":"34.24.165.231","time_stamp":"Thu Sep 24 04:25:23 2026","server_id":"46824fc494f03034e6b98e26d7a2d7a06b25f0b7","client_port":60808,"host_ip":"212.186.116.154","host_port":443,"unique_id":"179021672334.482807","is_interrupted":true,"request":{"method":"POST","http_version":"1.1","hostname":"ocean.spiess-vienna.at","uri":"/","headers":{"Host":"ocean.spiess-vienna.at","User-Agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36","Accept-Encoding":"gzip, deflate","Accept":"*/*","Next-Action":"x","Connection":"keep-alive","X-Nextjs-Request-Id":"380c9da3","Content-Type":"multipart/form-data; boundary=--------WebKitFormBoundary69537f7b584149fc","Content-Length":"748"}},"response":{"http_code":403,"headers":{"Server":"nginx\u0000","Date":"Thu, 24 Sep 2026 02:25:23 GMT","Content-Length":"548","Content-Type":"text/html","Connection":"keep-alive"}},"producer":{"modsecurity":"ModSecurity v3.0.16 (Linux)","
...
show less
Web App Attack
Anonymous
2026-09-23 09:51:03
(6 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 08:42:13
(6 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.24.165.231 - - [23/Sep/2026:10:42:07 +0200] "GET /.git/config HTTP/1.1" 301 644 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-09-23 08:36:13
(6 days ago)
[Wed Sep 23 08:36:12.354442 2026] [security2:error] [pid 3863534:tid 3863534] [client 34.24.165.231: ...
show more
[Wed Sep 23 08:36:12.354442 2026] [security2:error] [pid 3863534:tid 3863534] [client 34.24.165.231:40402] [client 34.24.165.231] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "onderdelen.fambus.nl"] [uri "/"] [unique_id "arOPfD31_UQFU8DOyiSE_AAAAAg"]
[Wed Sep 23 08:36:12.483876 2026] [security2:error] [pid 3863534:tid 3863534] [client 34.24.165.231:40402] [client 34.24.165.231] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [
...
show less
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 11:20:04
(6 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 22:39:38
(1 week ago)
20 attempts against mh-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 16:58:23
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack