🇿🇦
conure.sh
2026-09-12 12:01:25
(17 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 3s
Web App Attack
🇧🇬
Stoyko Stoykov
2026-09-12 11:59:47
(17 hours ago)
34.32.103.253 - - [12/Sep/2026:14:59:47 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X ...
show more
34.32.103.253 - - [12/Sep/2026:14:59:47 +0300] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:53:27
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:53:20.487930 2026] [security2:error] [pid 22743:tid 22743] [client 34.32.103.253:60098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.karensperling.com"] [uri "/.git/config"] [unique_id "aqUvICJGF6pGBk8qdWsVJgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
sthoyer.de
2026-09-12 10:13:04
(19 hours ago)
34.32.103.253 - - [12/Sep/2026:12:13:02 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; L ...
show more
34.32.103.253 - - [12/Sep/2026:12:13:02 +0200] "GET /.env HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.103.253 - - [12/Sep/2026:12:13:02 +0200] "GET /.env.local HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.103.253 - - [12/Sep/2026:12:13:02 +0200] "GET /.env.production HTTP/1.1" 302 495 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
Lino Project
2026-09-12 08:54:00
(21 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
🇺🇸
TPI-Abuse
2026-09-12 08:11:52
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 04:11:48.026229 2026] [security2:error] [pid 4263:tid 4263] [client 34.32.103.253:59324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stattransllc.com"] [uri "/.git/config"] [unique_id "aqUJRC9LrF6cs_ZdKfko1AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 07:56:36
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:56:31.516497 2026] [security2:error] [pid 22904:tid 22904] [client 34.32.103.253:58236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.starwarsrules.com"] [uri "/.git/config"] [unique_id "aqUFrwJzYZlCL4614lWzFwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-12 07:18:51
(22 hours ago)
Malware host detected by rbl.malware.expert. RBL lookup of 253.103.32.34.rbl.malware.expert succeede ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 253.103.32.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-12 07:10:42
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 03:10:34.276282 2026] [security2:error] [pid 7149:tid 7149] [client 34.32.103.253:39936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stansmarshservices.com"] [uri "/.git/config"] [unique_id "aqT66tYG1hJGHhvFu9qt0wAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-12 06:36:04
(23 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇵🇱
miriks
2026-09-12 06:32:06
(23 hours ago)
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
🇮🇹
sssrit
2026-09-12 05:53:30
(1 day ago)
34.32.103.253 - - [12/Sep/2026:07:53:29 +0200] "GET /phpinfo.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 ...
show more
34.32.103.253 - - [12/Sep/2026:07:53:29 +0200] "GET /phpinfo.php HTTP/1.1" 404 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
CBJ
2026-09-12 05:31:49
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 04:17:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.103.253 (253.103.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:17:47.008143 2026] [security2:error] [pid 13331:tid 13331] [client 34.32.103.253:51132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jti-group.com"] [uri "/.git/config"] [unique_id "aqTSa56gdoMMHBYUfIQ-kwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
srebrakowski.com
2026-09-12 03:40:54
(1 day ago)
crowdsec/crowdsecurity/appsec-vpatch
Brute-Force