🇺🇸
TPI-Abuse
2026-09-03 14:53:23
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:53:19.064487 2026] [security2:error] [pid 25169:tid 25169] [client 34.39.180.233:38024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "momihom.com"] [uri "/htdocs/.git/config"] [unique_id "apmJ3zwubxvu8DIG83lx1gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 13:45:02
(22 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-03 13:29:00
(23 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 12:10:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:10:45.964085 2026] [security2:error] [pid 27799:tid 27799] [client 34.39.180.233:45466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "26c.org"] [uri "/www/.git/config"] [unique_id "apljxQSkbSllLgja6F8E8wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-03 10:25:32
(1 day ago)
[Thu Sep 03 12:25:31.389699 2026] [:error] [pid 1593043:tid 1593043] [client 34.39.180.233:41686] Mo ...
show more
[Thu Sep 03 12:25:31.389699 2026] [:error] [pid 1593043:tid 1593043] [client 34.39.180.233:41686] ModSecurity: Warning. Matched "Operator `PmFromFile' with parameter `restricted-files.data' against variable `REQUEST_FILENAME' (Value: `/app/.git/config' ) [file "/usr/local/modsecurity-crs/rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "131"] [id "930130"] [rev ""] [msg "Restricted File Access Attempt"] [data "Matched Data: .git/ found within REQUEST_FILENAME: /app/.git/config"] [severity "2"] [ver "OWASP_CRS/4.30.0-dev"] [maturity "0"] [accuracy "0"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "OWASP_CRS/ATTACK-LFI"] [tag "capec/1000/255/153/126"] [uri "/app/.git/config"] [unique_id "178843113158.282289"] [ref "o5,5v4,16t:utf8toUnicode,t:urlDecodeUni,t:normalizePathWin"]
[Thu Sep 03 12:25:31.398839 2026] [:error] [pid 1593045:tid 1593045] [client 34.39.180.233:417
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 09:53:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:53:01.985795 2026] [security2:error] [pid 8771:tid 8771] [client 34.39.180.233:60704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.personalized-holiday-cards.com"] [uri "/src/.git/config"] [unique_id "aplDfXbg65X62NbHMxP2PwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SwinT
2026-09-03 08:00:11
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-03 06:10:41
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-03 05:57:45
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.39.180.233 (233.180.39.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:57:37.877028 2026] [security2:error] [pid 16045:tid 16055] [client 34.39.180.233:33526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "idssnc.us"] [uri "/htdocs/.git/config"] [unique_id "apkMUWF1FbgXD7MUzPNOgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-03 05:12:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack