๐ฉ๐ช
klaus_ph
2026-09-27 21:31:26
(1 day ago)
2026-09-26 23:14:55,042 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 34.39.169.114
...
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-26 12:23:30
(3 days ago)
2026-09-25 16:17:32,971 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.39.169.114
.. ...
show more
2026-09-25 16:17:32,971 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 34.39.169.114
...
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-24 07:29:12
(5 days ago)
[ti-26al] Web exploit scanning: 10 suspicious requests detected by fail2ban jail apache-scanner. Exa ...
show more
[ti-26al] Web exploit scanning: 10 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.39.169.114 - - [24/Sep/2026:09:28:59 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 6232 "-" "crusader-worker/1.0"
34.39.169.114 - - [24/Sep/2026:09:28:59 +0200] "GET /public/.git/config HTTP/1.1" 403 6232 "-" "crusader-worker/1.0"
34.39.169.114 - - [24/Sep/2026:09:28:59 +0200] "GET /.git/config HTTP/1.1" 403 6232 "-" "crusader-worker/1.0"
34.39.169.114 - - [24/Sep/2026:09:28:59 +0200] "GET /var/www/.git/config HTTP/1.1" 403 6232 "-" "crusader-worker/1.0"
34.39.169.114 - - [24/Sep/2026:09:28:59 +0200] "GET /src/.git/config HTTP/1.1" 403 6232 "-" "crusader-worker/1.0"
34.39.169.114 - - [24/Sep/2026:09:28:59 +020
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-24 05:15:05
(5 days ago)
[ThuSep2407:15:00.4965822026][security2:error][pid3185872:tid3185927][client34.39.169.114:0]ModSecur ...
show more
[ThuSep2407:15:00.4965822026][security2:error][pid3185872:tid3185927][client34.39.169.114:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"cst-ranghetti.ch.136-243-54-122.cpanel.site\"][uri\"/html/.git/config\"][unique_id\"arSx1PBLwgVqP_Lj53GFHQAAAE0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:35:14
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:35:11.753107 2026] [security2:error] [pid 31089:tid 31089] [client 34.39.169.114:56220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "criarteste.com"] [uri "/.git/config"] [unique_id "arSofzSokay7G1_D8Qn8UgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-09-24 01:53:30
(5 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-09-24 01:40:40
(5 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 01:15:06
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:23:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:23:38.634894 2026] [security2:error] [pid 10895:tid 10895] [client 34.39.169.114:40764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cook-islands-boat-registration.com"] [uri "/site/.git/config"] [unique_id "arRfeq24Kltw_S9Am0bKSwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:16:51
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:16:45.243418 2026] [security2:error] [pid 4220:tid 4225] [client 34.39.169.114:47538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coldwave.net"] [uri "/public/.git/config"] [unique_id "arRPzY5F62NAYu2ILx9sGgAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:20:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:20:29.790774 2026] [security2:error] [pid 16143:tid 16143] [client 34.39.169.114:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cdn-3.socialstudiesforkids.com"] [uri "/app/.git/config"] [unique_id "arQYbeMxGXVLUKDzXJyh2wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-23 15:58:09
(6 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:27:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:27:05.671399 2026] [security2:error] [pid 28796:tid 28796] [client 34.39.169.114:43956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buggyshop.org"] [uri "/public/.git/config"] [unique_id "arPvybTGcXPH1L3VzRtgXwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-23 13:56:22
(6 days ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 13:21:55
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.169.114 (114.169.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 09:21:48.258035 2026] [security2:error] [pid 3120:tid 3120] [client 34.39.169.114:53738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.mosherpit.com"] [uri "/.git/config"] [unique_id "arPSbJZ57RsMh2kw3t04RgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack