๐ฌ๐ง
consul.to
2026-09-02 06:45:19
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:21:02
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:20:55.366710 2026] [security2:error] [pid 13691:tid 13691] [client 34.30.114.7:46764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eventsetcinc.com"] [uri "/htdocs/.git/config"] [unique_id "apeyN6cA4I3uPDmHRhnDPAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-09-02 05:13:58
(3 weeks ago)
12 attacks on VC URLs:
GET /html/.git/config HTTP/1.1
Hacking
Anonymous
2026-09-02 02:47:34
(3 weeks ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
CoreTech srl
2026-09-02 02:08:57
(3 weeks ago)
cloudlinux2 fail2ban: 2026-09-02 04:03:56,725 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-02 04:03:56,725 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 136.107.199.186cloudlinux2 fail2ban: 2026-09-02 04:04:34,086 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.150.254.229 - 2026-09-02 04:04:33cloudlinux2 fail2ban: 2026-09-02 04:05:26,049 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.76.54.156cloudlinux2 fail2ban: 2026-09-02 04:05:34,504 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.30.114.7 - 2026-09-02 04:05:34cloudlinux2 fail2ban: 2026-09-02 04:05:34,563 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.30.114.7 - 2026-09-02 04:05:34cloudlinux2 fail2ban: 2026-09-02 04:05:34,478 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.30.114.7 - 2026-09-02 04:05:34cloudlinux2 fail2ban: 2026-09-02 04:05:34,535 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.30.114.7 - 2026-09-02 04:05:34cloudlinux2 fail2ban: 2026-09-02 04:05:34,494
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-02 00:45:49
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:45:42.864699 2026] [security2:error] [pid 4750:tid 4750] [client 34.30.114.7:45396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.daviddenotaris.com"] [uri "/html/.git/config"] [unique_id "apdxthWBu4C3Ng6OMlFwKAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rzk
2026-09-02 00:02:04
(3 weeks ago)
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-eve ...
show more
CrowdSec scenario: crowdsecurity/http-sensitive-files. Banned by Koru Cloud platform after multi-event detection. ASN: GOOGLE-CLOUD-PLATFORM. Country: US. Timestamp: 2026-09-02T00:02:03+00:00.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:57:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:57:45.522705 2026] [security2:error] [pid 32228:tid 32228] [client 34.30.114.7:43098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomslawmd.com"] [uri "/public/.git/config"] [unique_id "apdYaa379LOWrFaRTgQ02wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 21:14:28
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:14:20.522042 2026] [security2:error] [pid 12562:tid 12562] [client 34.30.114.7:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nyemdr.com"] [uri "/wordpress/.git/config"] [unique_id "apdALE4Gn1MUuzy6Ofou4QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 18:58:39
(3 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 18:20:23
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:20:14.932087 2026] [security2:error] [pid 12857:tid 12857] [client 34.30.114.7:54082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.infinite-e.com"] [uri "/backend/.git/config"] [unique_id "apcXXnQOuny-QrvdpjTG6QAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Vianpyro
2026-09-01 16:14:57
(3 weeks ago)
Honeypot: 26 request(s) in 0 min. Paths: /wordpress/.git/config, /api/.git/config, /htdocs/.git/conf ...
show more
Honeypot: 26 request(s) in 0 min. Paths: /wordpress/.git/config, /api/.git/config, /htdocs/.git/config, /app/.git/config, /html/.git/config. Method(s): GET. UA: crusader-worker/1.0. ASN: 396982 (Google LLC).
show less
Web App Attack
Bad Web Bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 13:32:03
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:31:58.285087 2026] [security2:error] [pid 14455:tid 14482] [client 34.30.114.7:57614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "behaviorhealth.org"] [uri "/src/.git/config"] [unique_id "apbTzgv1WtJN8w5qpqdb8wAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:51:57
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:51:53.246510 2026] [security2:error] [pid 22788:tid 22788] [client 34.30.114.7:47614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pundtlaw.com"] [uri "/html/.git/config"] [unique_id "apauSd8LCzHhU01ITnUsfgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:21:26
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.30.114.7 (7.114.30.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:21:18.667004 2026] [security2:error] [pid 29323:tid 29583] [client 34.30.114.7:35584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rawsynergy.com"] [uri "/app/.git/config"] [unique_id "apanHoL9jUd1Jc6zHxv-GQAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack