๐บ๐ธ
TPI-Abuse
2026-09-01 13:23:03
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:22:57.447968 2026] [security2:error] [pid 9852:tid 9852] [client 34.26.5.143:60766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lenosillevis.com"] [uri "/.git/config"] [unique_id "apbRsfUrRcVDDq9v-1woOAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-01 12:27:23
(2 weeks ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-01 09:37:49
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 08:25:20
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:25:11.631845 2026] [security2:error] [pid 32340:tid 32340] [client 34.26.5.143:34358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemritz.org.shtondo.com"] [uri "/.git/config"] [unique_id "apaL51FAfaeJ3N0Jf9gamgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-01 08:18:38
(2 weeks ago)
[TueSep0110:18:35.0657242026][security2:error][pid2454218:tid2454429][client34.26.5.143:0]ModSecurit ...
show more
[TueSep0110:18:35.0657242026][security2:error][pid2454218:tid2454429][client34.26.5.143:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"lemox.ch\"][uri\"/\"][unique_id\"apaKW4IQKcDbU5vfA8rLtAAAAUI\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 07:54:34
(2 weeks ago)
34.26.5.143 - - [01/Sep/2026:09:54:30 +0200] "GET /.git/config HTTP/1.1" 403 516 "-" "Mozilla/5.0 (W ...
show more
34.26.5.143 - - [01/Sep/2026:09:54:30 +0200] "GET /.git/config HTTP/1.1" 403 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.26.5.143 - - [01/Sep/2026:09:54:30 +0200] "GET /.git/config HTTP/1.1" 403 516 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.26.5.143 - - [01/Sep/2026:09:54:31 +0200] "GET /.git/config HTTP/1.1" 403 516 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.26.5.143 - - [01/Sep/2026:09:54:28 +0200] "GET / HTTP/1.1" 301 4792 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.26.5.143 - - [01/Sep/2026:09:54:29 +0200] "GET / HTTP/1.1" 301 4792 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.26.5.143 - - [01/Sep/2026:09:5
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 05:33:11
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:33:03.445788 2026] [security2:error] [pid 23489:tid 23489] [client 34.26.5.143:49488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemay.design"] [uri "/.git/config"] [unique_id "apZjj1u_F06n6rp8bedzbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 05:27:24
(2 weeks ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-01 05:27 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 02:53:07
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-01 02:35:05
(2 weeks ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-01 01:52:06
(2 weeks ago)
[da.kdns.gr] httpd-config-scan: sites=www.leitz.gr; logs=/var/log/httpd/domains/leitz.gr.log; sample ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.leitz.gr; logs=/var/log/httpd/domains/leitz.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
Anonymous
2026-09-01 01:40:02
(2 weeks ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:45:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.26.5.143 (143.5.26.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:45:49.733233 2026] [security2:error] [pid 18228:tid 18228] [client 34.26.5.143:53700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "liveinbirminghamalabama.com"] [uri "/.git/config"] [unique_id "apWTnZuO8Sxr7h3hsW8TXAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Live Home Cams
2026-08-31 14:43:18
(2 weeks ago)
WebApp brute force attack detected. Multiple file scanning attempts from 34.26.5.143. Detected by fa ...
show more
WebApp brute force attack detected. Multiple file scanning attempts from 34.26.5.143. Detected by fail2ban.
show less
Web App Attack
Brute-Force
๐ณ๐ฑ
Mangelot Hosting
2026-08-31 13:26:58
(2 weeks ago)
(modsecurity) srv104 ModSecurity 34.26.5.143 (US/United States/143.5.26.34.bc.googleusercontent.com) ...
show more
(modsecurity) srv104 ModSecurity 34.26.5.143 (US/United States/143.5.26.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack