🇧🇪
sid3windr
2026-09-06 08:11:58
(20 hours ago)
GET /.git/config (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
🇩🇪
LRob
2026-09-06 05:01:19
(23 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /www/.git/config (+10 more) | 2026-09-06 05:01 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:57:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:57:12.306758 2026] [security2:error] [pid 16758:tid 16758] [client 34.38.87.107:36200] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brokenglasstelecom.lahamradio.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brokenglasstelecom.lahamradio.com"] [uri "/backup.sql"] [unique_id "apzkmPhTvxCxjl1Y2LU15wAAAH4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 03:18:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 23:18:39.487199 2026] [security2:error] [pid 30727:tid 30746] [client 34.38.87.107:38456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barrywillis.org"] [uri "/wordpress/.git/config"] [unique_id "apzbj1yjTaewCShlwzfO0wAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 02:23:38
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:05:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:05:20.333573 2026] [security2:error] [pid 30704:tid 30704] [client 34.38.87.107:34024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop698.org"] [uri "/html/.git/config"] [unique_id "apyuQOgNDwNEWQdm4DmixgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-05 22:46:05
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:24:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:24:27.646916 2026] [security2:error] [pid 17209:tid 17209] [client 34.38.87.107:37674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manty.com"] [uri "/.git/config"] [unique_id "apyWm8NuNFFPRnb4K6lE0QAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:03:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.38.87.107 (107.87.38.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:03:43.998875 2026] [security2:error] [pid 4293:tid 4293] [client 34.38.87.107:36242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rondeal.com"] [uri "/src/.git/config"] [unique_id "apyDrw3oqbTGyhSL282alwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 20:30:17
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
factor1
2026-09-05 13:17:00
(1 day ago)
CrowdSec at thor Reports Abuse
Web App Attack
Anonymous
2026-09-05 02:22:45
(2 days ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack