๐น๐ท
ycoskun41
2026-07-27 14:54:26
(4 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 14:39:17
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐จ๐ญ
4server
2026-07-27 14:29:35
(5 hours ago)
[MonJul2716:29:28.1727592026][security2:error][pid836081:tid836409][client34.244.211.134:0]ModSecuri ...
show more
[MonJul2716:29:28.1727592026][security2:error][pid836081:tid836409][client34.244.211.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"motogiro.com.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"amdrSGTsr99CRjwaFi-p7gAAAQs\"]
show less
Hacking
Web App Attack
๐ฟ๐ฆ
conure
2026-07-27 13:05:48
(6 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 11:36:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 07:36:50.940987 2026] [security2:error] [pid 476:tid 476] [client 34.244.211.134:40740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "motioncontrolpartners.com"] [uri "/.git/config"] [unique_id "amdC0i7L7jzeC1QT_c1oGwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-07-26 03:45:09
(1 day ago)
Scanning for exploits - /.env
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-25 22:07:03
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-24.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-07-25 16:24:33
(2 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฟ
Antinson
2026-07-25 11:42:08
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-24 19:00:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:00:17.161788 2026] [security2:error] [pid 668128:tid 668128] [client 34.244.211.134:48502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clarkns.ryanc.net"] [uri "/.git/config"] [unique_id "amO2QZaTyTdh8pNwJj3IrgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:43:09
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:43:05.558542 2026] [security2:error] [pid 907825:tid 907825] [client 34.244.211.134:56408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brewhaha.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "amOkKQ8zrMiDU6jaIvKzfAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 11:14:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 07:14:15.566059 2026] [security2:error] [pid 3594681:tid 3594681] [client 34.244.211.134:39008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.civilwarzone.andrewrmarshall.com"] [uri "/.git/config"] [unique_id "amNJB12StRAB4WR331uH8AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-24 09:42:46
(3 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 08:55:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.co ...
show more
(mod_security) mod_security (id:210492) triggered by 34.244.211.134 (ec2-34-244-211-134.eu-west-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:55:44.789956 2026] [security2:error] [pid 10309:tid 10309] [client 34.244.211.134:36790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cityofhaleyville.com"] [uri "/.git/config"] [unique_id "amMokM8s2diaapHwgoP3fAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-24 04:56:46
(3 days ago)
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js ...
show more
IM360 WAF: RCE via prototype pollution in React Server Components < 19.0.1/19.1.2/19.2.1 or Next.js < 15.0.5/16.0.7 (CVE-2025-55182, CVE-2025-66478)
show less
Hacking