🇸🇪
vaia.cloud
2026-09-07 16:45:02
(7 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:20:08
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:20:04.069162 2026] [security2:error] [pid 10601:tid 10601] [client 34.32.54.147:34598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitnikarch.com"] [uri "/.git/config"] [unique_id "ap66BDwh4_jQ5uGx_1YxXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Epimetheus
2026-09-07 13:08:44
(11 hours ago)
Unauthorized access attempts:
[GET] /gcp-sa.json
[GET] /core/phpinfo.php
[GET] /site/phpinfo.php
[G ...
show more
Unauthorized access attempts:
[GET] /gcp-sa.json
[GET] /core/phpinfo.php
[GET] /site/phpinfo.php
[GET] /server-status.php
[GET] /old/phpinfo.php
[GET] /queue/.env
[GET] /sitemaps/.env
[GET] /en/.env
[GET] /vue/.env
[GET] /panel/.env
[GET] /yii/.env
[GET] /dev/.env
[GET] /live/.env
[GET] /shared/.env
[GET] /.env.stage
[GET] /.env.swp
[GET] /.env.dev
[GET] /.env.example
[GET] /.env.remote
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-07 12:52:24
(11 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/147.54.32.34.bc.googleusercontent ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/147.54.32.34.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:30:17
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:30:10.493082 2026] [security2:error] [pid 25605:tid 25605] [client 34.32.54.147:40606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mithryl.com"] [uri "/.git/config"] [unique_id "ap6uUmqbuCztErhWWvwTFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 12:09:12
(12 hours ago)
Excessive multi-domain requests
Brute-Force
🇨🇭
zynex
2026-09-07 12:06:52
(12 hours ago)
URL Probing: /.env
Web App Attack
🇳🇴
jad-abuse
2026-09-07 11:04:20
(13 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 275 hits.
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:17:26
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:17:21.601236 2026] [security2:error] [pid 3920:tid 3920] [client 34.32.54.147:50588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchell-hunt.com"] [uri "/.git/config"] [unique_id "ap6PMWF_ViOXU3at_RiYcgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dpsbs
2026-09-07 09:42:36
(14 hours ago)
multiple ips intrustions detected
Hacking
🇩🇪
ger-stg-sifi1
2026-09-07 09:32:59
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:25:27
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.54.147 (147.54.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:25:21.034836 2026] [security2:error] [pid 13013:tid 13013] [client 34.32.54.147:55588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "miszewski.com"] [uri "/.git/config"] [unique_id "ap508VjRzlTMD2yWIc61zgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-07 07:58:40
(16 hours ago)
XORP (haproxy): 12x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 12x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
🇫🇷
Octopuce
2026-09-06 19:38:17
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇳🇱
e.fierstra
2026-09-06 19:09:22
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack