๐ฉ๐ช
IVski.com
2026-09-16 16:25:38
(12 hours ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-16 15:59:14
(12 hours ago)
T: f2b 404 5x
Web App Attack
Anonymous
2026-09-16 13:44:15
(14 hours ago)
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-09-16 13:15:58
(15 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:02:31
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:02:25.942313 2026] [security2:error] [pid 19406:tid 19419] [client 34.32.77.155:59852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcp.volcano-sa.com"] [uri "/.git/config"] [unique_id "aqqTYXFyyJRQrflL08d0AgAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 08:14:34
(20 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: DE, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: DE, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:38:24
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:38:19.406387 2026] [security2:error] [pid 11223:tid 11223] [client 34.32.77.155:53628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michleen-collins.com"] [uri "/.git/config"] [unique_id "aqpHawtVdPCyWdcXl_acdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 04:26:59
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
Zundapper
2026-09-16 04:14:08
(1 day ago)
34.32.77.155 - - [16/Sep/2026:06:14:06 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; ...
show more
34.32.77.155 - - [16/Sep/2026:06:14:06 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.77.155 - - [16/Sep/2026:06:14:07 +0200] "GET /info HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.77.155 - - [16/Sep/2026:06:14:07 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.77.155 - - [16/Sep/2026:06:14:07 +0200] "GET /_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.32.77.155 - - [16/Sep/2026:06:14:07 +0200] "GET /webroot/index.php/_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
๐ซ๐ฎ
paissangroup
2026-09-16 03:29:18
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-16 03:28:58
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:25:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:24:52.991775 2026] [security2:error] [pid 18419:tid 18419] [client 34.32.77.155:50556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaeltravis.com"] [uri "/.git/config"] [unique_id "aqn99DpVtulKVtMfX8K3rwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-16 02:07:16
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:53:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:53:01.047689 2026] [security2:error] [pid 6818:tid 6818] [client 34.32.77.155:45232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelsabbey.org"] [uri "/.git/config"] [unique_id "aqn2fVmoGwq1jcDdX57F4AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:38:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.77.155 (155.77.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:37:57.413902 2026] [security2:error] [pid 3508:tid 3508] [client 34.32.77.155:44326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "michaelpmcgrath.com"] [uri "/.git/config"] [unique_id "aqny9QTiXhnefeWrvqh07wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack