🇺🇸
TPI-Abuse
2026-09-10 08:30:12
(54 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 04:30:05.743160 2026] [security2:error] [pid 1222:tid 1222] [client 34.32.84.53:50672] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bright-enterprise.com"] [uri "/.git/config"] [unique_id "aqJqjdq0n5qRF61nSBmkmAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 04:21:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:20:57.729253 2026] [security2:error] [pid 30175:tid 30175] [client 34.32.84.53:49642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thresholddigital.com"] [uri "/.git/config"] [unique_id "aqIwKSAbLPmijDxBnVDQZwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 03:11:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:11:12.895507 2026] [security2:error] [pid 1545:tid 1545] [client 34.32.84.53:47240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "threewild.com"] [uri "/.git/config"] [unique_id "aqIf0GmttPqwY6jGh7QAFgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-10 01:47:02
(7 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇳🇱
Savvii
2026-09-10 01:04:45
(8 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 00:26:19
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-09 23:26:42
(9 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 19:16:19
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 15:16:10.969314 2026] [security2:error] [pid 11668:tid 11668] [client 34.32.84.53:53964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shtondo.com"] [uri "/.git/config"] [unique_id "aqGwelxXymDQPxX37mjIhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-09 17:54:52
(15 hours ago)
512 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇦🇺
2000cn.com.au
2026-09-09 17:25:06
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-09 16:30:01
(16 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 15:06:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:06:28.898654 2026] [security2:error] [pid 1042:tid 1042] [client 34.32.84.53:54934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "opticasprisma.com"] [uri "/.git/config"] [unique_id "aqF19HnHvwuLr8fAbQqYLwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 14:17:28
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.84.53 (53.84.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:17:22.934824 2026] [security2:error] [pid 22710:tid 22710] [client 34.32.84.53:51110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lcssouth.com"] [uri "/.git/config"] [unique_id "aqFqcoVb2ecx6cwEBU_APAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 13:58:56
(19 hours ago)
cloudlinux2 fail2ban: 2026-09-09 15:55:40,195 fail2ban.filter [1892]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-09 15:55:40,195 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:39cloudlinux2 fail2ban: 2026-09-09 15:55:40,308 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:40cloudlinux2 fail2ban: 2026-09-09 15:55:40,224 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:40cloudlinux2 fail2ban: 2026-09-09 15:55:40,216 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:40cloudlinux2 fail2ban: 2026-09-09 15:55:40,243 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:40cloudlinux2 fail2ban: 2026-09-09 15:55:40,365 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.32.84.53 - 2026-09-09 15:55:40cloudlinux2 fail2ban: 2026-09-09 15:55:40,353 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 34.32.84.53cloudlinux2 fail2ban: 2026-09-09
show less
Brute-Force
🇫🇷
masterguru
2026-09-09 12:15:36
(21 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking