๐ฎ๐น
CoreTech srl
2026-08-29 05:48:57
(47 minutes ago)
cloudlinux2 fail2ban: 2026-08-29 07:44:47,531 fail2ban.filter [1478]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-29 07:44:47,531 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 212.43.159.80 - 2026-08-29 07:44:47cloudlinux2 fail2ban: 2026-08-29 07:45:13,871 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.24.24.174 - 2026-08-29 07:45:13cloudlinux2 fail2ban: 2026-08-29 07:45:13,879 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.24.24.174 - 2026-08-29 07:45:13cloudlinux2 fail2ban: 2026-08-29 07:45:13,845 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.24.24.174 - 2026-08-29 07:45:13cloudlinux2 fail2ban: 2026-08-29 07:45:14,372 fail2ban.filter [1478]: INFO [recidive] Found 34.24.24.174 - 2026-08-29 07:45:14cloudlinux2 fail2ban: 2026-08-29 07:45:13,896 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 34.24.24.174 - 2026-08-29 07:45:13cloudlinux2 fail2ban: 2026-08-29 07:45:14,365 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Ban 34.24.24.174cloudlinux2 fail2ban: 2026-08-29 07:
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-29 04:20:01
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:19:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.24.174 (174.24.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.24.174 (174.24.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:19:22.458754 2026] [security2:error] [pid 2298:tid 2298] [client 34.24.24.174:57502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "celebritybikinigossip.com"] [uri "/.git/config"] [unique_id "apJBqjqfatJtXHprMJNCPwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 01:40:01
(4 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
โจ
2026-08-29 00:06:14
(6 hours ago)
Domain : childaid.org.uk
Rule : config
2026-08-29 00:05:00 W3SVC29 PLESK76 217.194.212.111 GET /var/ ...
show more
Domain : childaid.org.uk
Rule : config
2026-08-29 00:05:00 W3SVC29 PLESK76 217.194.212.111 GET /var/www/.git/config - 443 - 34.24.24.174 HTTP/1.1 crusader-worker/1.0 - - www.childaid.org.uk 404 8 0 316 110 100 - -
show less
Hacking
SQL Injection
๐บ๐ธ
mnsf
2026-08-29 00:05:52
(6 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-28 23:50:49
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /var/www/.git/config (+11 more) | 2026-08-28 23:50 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:30
(8 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
rollenspiel.network
2026-08-28 21:50:41
(8 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-28 20:13:00
(10 hours ago)
[28/Aug/2026:23:13:00 +0300] -- 34.24.24.174 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[28/Aug/2026:23:13:00 +0300] -- 34.24.24.174 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-28 13:37:22
(16 hours ago)
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /src/.git/config HTTP/1.1" 404 46273 "-" "crusade ...
show more
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /src/.git/config HTTP/1.1" 404 46273 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 46272 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /site/.git/config HTTP/1.1" 404 46272 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /html/.git/config HTTP/1.1" 404 46271 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /public/.git/config HTTP/1.1" 301 548 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /app/.git/config HTTP/1.1" 404 46272 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /htdocs/.git/config HTTP/1.1" 301 548 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /www/.git/config HTTP/1.1" 301 542 "-" "crusader-worker/1.0"
34.24.24.174 - - [28/Aug/2026:15:37:11 +0200] "GET /backend/.git/config HTTP/1.1
show less
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-08-28 12:55:04
(17 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:07:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.24.24.174 (174.24.24.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.24.174 (174.24.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:07:35.410643 2026] [security2:error] [pid 12936:tid 12936] [client 34.24.24.174:38130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alextra.org"] [uri "/html/.git/config"] [unique_id "apBu16F1BfFP9xLJ5eDsOwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:24:39
(1 day ago)
[ns67.kdns.gr] httpd-config-scan: sites=www.panel.kweb.gr; logs=/var/www/vhosts/system/panel.kapaweb ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=www.panel.kweb.gr; logs=/var/www/vhosts/system/panel.kapaweb.gr/logs/proxy_access_log,/var/www/vhosts/system/panel.kapaweb.gr/logs/proxy_access_ssl_log; samples=/public/.git/config | /www/.git/config | /src/.git/config
show less
Hacking
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-27 14:34:12
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot