๐ณ๐ฑ
Site.eu
2026-09-17 02:18:02
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-17 02:13:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:13:22.161687 2026] [security2:error] [pid 26100:tid 26100] [client 34.32.123.213:50330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulsingdahlsen.com"] [uri "/.git/config"] [unique_id "aqtMwrBNNiLDWhuIDQm1lwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-17 02:12:46
(3 hours ago)
[Thu Sep 17 12:12:45.936859 2026] [security2:error] [pid 448614] [client 34.32.123.213:45574] [clien ...
show more
[Thu Sep 17 12:12:45.936859 2026] [security2:error] [pid 448614] [client 34.32.123.213:45574] [client 34.32.123.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/"] [unique_id "aqtMnenBV-WOuu-Z6W-3UwAAAAM"]
...
show less
Web App Attack
๐ณ๐ฑ
oisecnet
2026-09-16 21:02:37
(8 hours ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-16. 308 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-16. 308 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐ณ๐ฑ
Eric
2026-09-16 15:34:55
(14 hours ago)
[Wed Sep 16 15:34:54.639653 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42 ...
show more
[Wed Sep 16 15:34:54.639653 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42210] [client 34.32.123.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mail.fambus.nl"] [uri "/"] [unique_id "aqq3HiAdn6bWXzEDbsn8GwAAABo"]
[Wed Sep 16 15:34:54.669965 2026] [security2:error] [pid 178299:tid 178299] [client 34.32.123.213:42210] [client 34.32.123.213] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:06:37
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:06:34.581889 2026] [security2:error] [pid 18607:tid 18607] [client 34.32.123.213:33364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.ez1productions.com"] [uri "/.git/config"] [unique_id "aqqwemZUnR1ic0EGaV5tYQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:43:20
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:43:13.503130 2026] [security2:error] [pid 26973:tid 26973] [client 34.32.123.213:35252] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.exhibitfactory.com"] [uri "/.git/config"] [unique_id "aqqrAUcpay5gu1AoEEOszQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
iulianh
2026-09-16 14:04:27
(15 hours ago)
80,443
Brute-Force
SSH
๐ต๐ฑ
gandaflux
2026-09-16 12:28:29
(17 hours ago)
34.32.123.213 [redacted-domain] - [16/Sep/2026:14:28:28 +0200] "GET /.git/config HTTP/1.1" 403 158 " ...
show more
34.32.123.213 [redacted-domain] - [16/Sep/2026:14:28:28 +0200] "GET /.git/config HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.123.213 [redacted-domain] - [16/Sep/2026:14:28:28 +0200] "GET /.env HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.123.213 [redacted-domain] - [16/Sep/2026:14:28:28 +0200] "GET /.env.local HTTP/1.1" 403 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
oja
2026-09-16 09:53:52
(19 hours ago)
Aggressive web scanner
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-16 09:03:21
(20 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
aks4226
2026-09-16 07:20:20
(22 hours ago)
Attacking common web applications. (n01)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:47:49
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.123.213 (213.123.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:47:44.580989 2026] [security2:error] [pid 22592:tid 22592] [client 34.32.123.213:41710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.nutandboltguy.com"] [uri "/.git/config"] [unique_id "aqotgMWowTs4ycIQrVWS2QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 04:36:39
(1 day ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.env ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-16 03:52:31
(1 day ago)
(modsecurity) srv102 ModSecurity 34.32.123.213 (DE/Germany/213.123.32.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv102 ModSecurity 34.32.123.213 (DE/Germany/213.123.32.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack